Fake AI Chatbot Ads Steal Passwords, MFA Codes
Key Takeaways A sophisticated phishing campaign is impersonating popular AI chatbots like ChatGPT, Claude, and Gemini through deceptive ads. The attackers employ convincing fake websites and use live...
Key Takeaways
- A sophisticated phishing campaign is impersonating popular AI chatbots like ChatGPT, Claude, and Gemini through deceptive ads.
- The attackers employ convincing fake websites and use live human operators to guide victims through fraudulent login processes.
- This campaign aims to steal passwords and multi-factor authentication (MFA) codes, targeting advertising professionals.
- Compromised advertising accounts can lead to unauthorized ad spending, fraudulent campaigns, and exposure of client billing information.
- The attackers utilize a “browser-in-browser” technique to create highly realistic fake login windows, making detection difficult for unsuspecting users.
Cybercriminals are leveraging the widespread adoption of artificial intelligence by creating elaborate fake advertisements for popular AI chatbots such as ChatGPT, Claude, and Gemini. These deceptive campaigns are designed to harvest user credentials, including passwords and multi-factor authentication (MFA) codes, through highly convincing phishing tactics.
Table Of Content
Unlike traditional malware distribution, this operation relies on sophisticated social engineering. Victims are directed to meticulously crafted imitation websites where live human operators engage them, guiding them through a series of fraudulent sign-in prompts. This interactive approach significantly enhances the campaign’s realism and success rate.
The campaign begins with invitation emails, luring advertising professionals with promises of advanced campaign planning, spending audits, and seamless account integrations. This strategy mirrors previous attacks that exploited well-known technology brands, making the credential requests appear legitimate. Research by Island.io indicates that the attackers can manipulate the login flow, rejecting incorrect passwords, selecting specific authentication challenges, and redirecting victims after successful credential capture. Island.io said in a report, detailing hundreds of observed victim submissions, with the activity ongoing as of their publication on October 6, 2026.
Sophisticated Impersonation and User Interaction
The fake AI products offer specific lures to encourage account connection. For instance, ChatGPT impersonations offer “weekly Google Ads briefings,” Gemini pages promote “manager-account support,” and Claude features its own “advertising portal.” Other prominent AI brands, including Perplexity and Manus, are also being impersonated. A new lure, “Muse Ads,” emerged by September 16, just eight days after Meta announced its legitimate Muse product. This rapid deployment demonstrates the attackers’ agility in adapting to new trends. Researchers noted that the sign-in forms and fake browser windows for Muse Ads reused existing code from the broader phishing platform, highlighting the efficiency with which new product narratives are integrated into established malicious infrastructure.
A key technique employed is the “browser-in-browser” attack. When a user clicks “Connect,” a simulated browser window appears within the legitimate browser. This inner window displays a seemingly authentic address bar and lock icon, while the actual, malicious page remains hosted on the attacker’s infrastructure. This visual deception makes it exceedingly difficult for users to discern the fraud.
The phishing interface is highly adaptive, adjusting its appearance to mimic various operating systems, including Windows, macOS, iOS, and Android. Newer versions even replicate subtle details such as dark mode, mobile browser controls, and translucent toolbars. These granular touches enhance the illusion of authenticity without altering the real browser’s URL or origin.
Behind this sophisticated facade, the platform meticulously logs victim data, including device characteristics, geographical location, and submitted credentials. It retains up to three password attempts, allowing operators to falsely claim a password failure, request a retry, and capture every input provided by the victim. Human operators then dynamically select the next authentication step, attempting real logins in the background. The system supports various MFA prompts, including SMS codes, authenticator app codes, Google approvals, QR code verification, number matching, and Okta push requests. A “waiting” screen keeps victims engaged while the attacker processes the stolen information and determines the subsequent request.
Shared Infrastructure and Account Protection
The same underlying Next.js and Socket.IO platform underpins these AI advertising phishing pages, as well as unrelated refund claim and fake recruitment sites. Researchers identified one backend server linked to 73 archived scans across 25 different domains between May 27 and June 20, demonstrating a shared infrastructure for diverse malicious campaigns. Exposed older source code from public GitHub repositories further revealed consistent routes, the three-password retry mechanism, and Telegram-based control functionalities.
The platform reconstructs login interfaces locally instead of directly proxying the identity provider’s website. This method makes the malicious traffic appear as normal application activity, evading detection by some security measures.
Compromised advertising accounts pose a significant risk, as they can be used to fund fraudulent advertising campaigns, or be sold on underground markets. Island.io warns that attackers might add their own administrators and diminish the legitimate owner’s access, prolonging the recovery process for weeks or even months. Furthermore, recruitment-themed lures present a distinct threat: employees who use corporate credentials when applying for external jobs could inadvertently expose their employer’s email, files, and business applications to unauthorized access.
What You Should Do
- Verify Authenticity: Always verify unexpected beta programs, advertising tools, or account connection requests by visiting the official vendor’s website directly, rather than clicking links in emails or ads.
- Inspect the Address Bar: Pay close attention to your browser’s outermost address bar. Do not rely on address bars or lock icons displayed within a web page, as these can be faked using “browser-in-browser” techniques.
- Implement Phishing-Resistant MFA: Organizations should prioritize the adoption of phishing-resistant authentication methods like passkeys and hardware-backed security keys (e.g., FIDO2/WebAuthn) to reduce reliance on easily intercepted passwords and codes.
- Monitor for Anomalies: Security teams should actively monitor for device-profiling requests, repeated password entry attempts, and operator-control events within their network traffic.
- Post-Compromise Audit: If an account is suspected of compromise, administrators must conduct a thorough review of not only the initial account but also all connected client accounts. Look for unfamiliar administrators, altered recovery details, and any unauthorized campaigns or spending.
Indicators of compromise (IoCs):-
| Type | Indicator | Description | ||
|---|---|---|---|---|
| Domain | account-sync-data.com |
Advertising phishing domain | ||
| Domain | ads-claude-beta.com |
Advertising phishing domain | ||
| Domain | ads-claude.com |
Advertising phishing domain | ||
| Domain | ads-team-openai.com |
Advertising phishing domain | ||
| Domain | adsmistral.com |
Advertising phishing domain | ||
| Domain | advertising-chatgpt.com |
Advertising phishing domain | advertising-gemini.com |
Advertising phishing domain |
| Domain | ai-ads-platform.com |
Advertising phishing domain | ||
| Domain | ai-brand-safety.com |
Advertising phishing domain | ||
| Domain | anthropic-ads-beta.com |
Advertising phishing domain | ||
| Domain | anthropic-ads-marketing.com |
Advertising phishing domain | ||
| Domain | anthropic-ads.com |
Advertising phishing domain | ||
| Domain | anthropic-beta-ads.com |
Advertising phishing domain | ||
| Domain | anthropic-crm-1.com |
Advertising phishing domain | ||
| Domain | anthropic-sponsored.com |
Advertising phishing domain | ||
| Domain | beta-anthropic.com |
Advertising phishing domain | ||
| Domain | beta-chatgpt.com |
Advertising phishing domain | ||
| Domain | beta-gemini-ads.com |
Advertising phishing domain | ||
| Domain | beta-manus.com |
Advertising phishing domain | ||
| Domain | beta-perplexity.com |
Advertising phishing domain | ||
| Domain | business-gemini.com |
Advertising phishing domain | ||
| Domain | chatgpt-advertise.com |
Advertising phishing domain | ||
| Domain | chatgpt-advertisement.com |
Advertising phishing domain | ||
| Domain | chatgpt-beta.com |
Advertising phishing domain | ||
| Domain | chatgpt-brief.com |
Advertising phishing domain | ||
| Domain | chatgpt-briefing.com |
Advertising phishing domain | ||
| Domain | chatgpt-monday-brief.com |
Advertising phishing domain | ||
| Domain | claude-ads-beta.com |
Advertising phishing domain | ||
| Domain | claude-ads-invitations.com |
Advertising phishing domain | ||
| Domain | claude-ads-portal.com |
Advertising phishing domain | ||
| Domain | claude-ads.ai |
Advertising phishing domain | ||
| Domain | claude-advertisement.com |
Advertising phishing domain | ||
| Domain | claude-advertisers.ai |
Advertising phishing domain | ||
| Domain | claude-advertisers.com |
Advertising phishing domain | ||
| Domain | claude-beta-invite.com |
Advertising phishing domain | ||
| Domain | claude-beta.com |
Advertising phishing domain | ||
| Domain | cursor-ads.com |
Advertising phishing domain | ||
| Domain | escrow-ads.com |
Advertising phishing domain | ||
| Domain | gemimi-ads.com |
Advertising phishing domain | ||
| Domain | gemini-ads-ai.com |
Advertising phishing domain | ||
| Domain | gemini-ads-invite.com |
Advertising phishing domain | ||
| Domain | gemini-ads-team.com |
Advertising phishing domain | ||
| Domain | gemini-ads.ai |
Advertising phishing domain | ||
| Domain | gemini-advertisers.com |
Advertising phishing domain | ||
| Domain | gemini-beta-invitations.com |
Advertising phishing domain | ||
| Domain | gemini-beta-invites.com |
Advertising phishing domain | ||
| Domain | gemini-business.com |
Advertising phishing domain | ||
| Domain | gemini-google-ads.com |
Advertising phishing domain | ||
| Domain | gemini-invitation.com |
Advertising phishing domain | ||
| Domain | gemini-invitations.com |
Advertising phishing domain | ||
| Domain | gennini-ads.com |
Advertising phishing domain | ||
| Domain | google-ads-sync.com |
Advertising phishing domain | ||
| Domain | invitation-anthropic.com |
Advertising phishing domain | ||
| Domain | leaks-entry.com |
Advertising phishing domain | ||
| Domain | leaksentry-security.com |
Advertising phishing domain | ||
| Domain | link-mcc.com |
Advertising phishing domain | ||
| Domain | manus-meta.im |
Advertising phishing domain | ||
| Domain | manusbymeta.com |
Advertising phishing domain | ||
| Domain | manusmeta.im |
Advertising phishing domain | ||
| Domain | mcc-account-sync.com |
Advertising phishing domain | ||
| Domain | mcc-invitation.com |
Advertising phishing domain | ||
| Domain | mcc-safety.com |
Advertising phishing domain | ||
| Domain | mcc-security.com |
Advertising phishing domain | ||
| Domain | mcc-verification.com |
Advertising phishing domain | ||
| Domain | metamanus.im |
Advertising phishing domain | ||
| Domain | monday-brief-claude.com |
Advertising phishing domain | ||
| Domain | museads.ai |
Advertising phishing domain | ||
| Domain | openai-ads.ai |
Advertising phishing domain | ||
| Domain | openai-advertisers.com |
Advertising phishing domain | ||
| Domain | openaiadsteam.com |
Advertising phishing domain | ||
| Domain | perplexity-advertising.com |
Advertising phishing domain | ||
| Domain | perplexity-beta-ads.com |
Advertising phishing domain | ||
| Domain | perplexity-beta.com |
Advertising phishing domain | ||
| Domain | safety-mcc.com |
Advertising phishing domain | ||
| Domain | security-ads.com |
Advertising phishing domain | ||
| Domain | security-mcc.com |
Advertising phishing domain | semrush-ai.com |
Advertising phishing domain |
| Domain | semrushads-ai.com |
Advertising phishing domain | ||
| Domain | sponsored-gemini.com |
Advertising phishing domain | ||
| Domain | sync-account-invite.com |
Advertising phishing domain | ||
| Domain | sync-account.com |
Advertising phishing domain | ||
| Domain | sync-ads-account.com |
Advertising phishing domain | ||
| Domain | sync-ads.com |
Advertising phishing domain | ||
| Domain | sync-business.com |
Advertising phishing domain | ||
| Domain | sync-mcc-account.com |
Advertising phishing domain | ||
| Domain | sync-mcc-data.com |
Advertising phishing domain | ||
| Domain | sync-mcc-team.com |
Advertising phishing domain | ||
| Domain | sync-tiktok.com |
Advertising phishing domain | ||
| Domain | verification-security.com |
Advertising phishing domain | ||
| Backend host | adsclaudeback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | anthropicadsback.onrender.com |
Advertising campaign backend | ||
| Backend host | backend-j02u.onrender.com |
Advertising campaign backend | ||
| Backend host | backend-production-6d75.up.railway.app |
Shared advertising, refund and recruitment backend | ||
| Backend host | backend-tg0j.onrender.com |
Advertising campaign backend | ||
| Backend host | chatgptadsback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | chatgptadsback.onrender.com |
Advertising campaign backend | ||
| Backend host | claudeadsback-production-67c1.up.railway.app |
Advertising campaign backend | ||
| Backend host | claudeadsback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | geminiback-5j1n.onrender.com |
Advertising campaign backend | ||
| Backend host | geminiback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | just-cooperation-production-f159.up.railway.app |
Advertising campaign backend | ||
| Backend host | manus2back-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | manusback-bahk.onrender.com |
Advertising campaign backend | ||
| Backend host | manusback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | manusback.onrender.com |
Advertising campaign backend | ||
| Backend host | mbackend-mdye.onrender.com |
Advertising campaign backend | ||
| Backend host | museadsback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | semrushback.onrender.com |
Advertising campaign backend | ||
| Backend host | syncgadsback.onrender.com |
Advertising campaign backend | ||
| Backend host | syncgoogleadsback-production-6100.up.railway.app |
Advertising campaign backend | ||
| Backend host | syncgoogleadsback-production-cde6.up.railway.app |
Advertising campaign backend | ||
| Backend host | syncgoogleadsback-production.up.railway.app |
Advertising campaign backend | ||
| Backend host | syncgoogleadsback.onrender.com |
Advertising campaign backend | ||
| Backend host | tbackend-production-39ca.up.railway.app |
Advertising campaign backend | ||
| Domain | confirm-payments.com |
Refund phishing domain | ||
| Domain | payment-confirm.com |
Refund phishing domain | ||
| Domain | payment-confirmation.com |
Refund phishing domain | ||
| Domain | payment-confirmations.com |
Refund phishing domain | ||
| Domain | payment-sync.com |
Refund phishing domain | ||
| Domain | payments-sync.com |
Refund phishing domain | ||
| Domain | refund-advertisers.com |
Refund phishing domain | ||
| Domain | sync-billing.com |
Refund phishing domain | ||
| Domain | sync-payment.com |
Refund phishing domain | ||
| Domain | sync-payments.com |
Refund phishing domain | ||
| Domain | adeccohr-calendly.com |
Recruitment phishing domain | ||
| Domain | adeccohr-jobs.com |
Recruitment phishing domain | ||
| Domain | apple-career.com |
Recruitment phishing domain | ||
| Domain | nikehr-jobs.com |
Recruitment phishing domain | ||
| Domain | talent-louisvuitton.com |
Recruitment phishing domain | ||
| Backend host | nikear.onrender.com |
Recruitment campaign backend | ||
| Backend host | zero39172-391920.onrender.com |
Recruitment campaign backend | ||
| Domain | careers-interview.com |
Recruitment phishing domain | ||
| Domain | ferrar.careers-interview.com |
Recruitment phishing domain | ||
| Domain | ferrari-invite.com |
Recruitment phishing domain | ||
| Domain | redbullapply.careers-appointment.com |
Recruitment phishing domain | ||
| Domain | tesla-careerapplication.com |
Recruitment phishing domain | ||
| Backend host | mango-back.onrender.com |
Recruitment campaign backend | ||
| Legitimate domain | accounts.google.com |
Spoofed address-bar destination, not attacker infrastructure | ||
| Legitimate service | api.ipify.org |
IP lookup service used in profiling; not independently malicious | ||
| Legitimate service | ipapi.co |
IP information service used in profiling; not independently malicious | ||
| API path | /api/create/user |
Creates a victim record | ||
| API path | /api/send/ip |
Receives device and IP profiling information | ||
| State field | google_uid |
Client-pattern detection artifact | ||
| State field | password_one |
Stores the first password submission | ||
| State field | password_two |
Stores the second password submission | ||
| State field | password_three |
Stores the third password submission | ||
| Control event | add-user |
Platform control-vocabulary artifact | ||
| Control event | update-user |
Platform control-vocabulary artifact | ||
| Control event | operator-command |
Delivers operator instructions | ||
| Control event | telegram-command |
Delivers Telegram-linked instructions | ||
| Operator command | /password |
Requests another password | ||
| Operator command | /2fa |
Requests an SMS code | ||
| Operator command | /authApp |
Requests an authenticator code | ||
| Operator command | /googlePrompt |
Displays a Google approval prompt | ||
| Operator command | /googleQrVerify |
Displays a supplied QR payload | ||
| Operator command | /verifyTap |
Displays a supplied tap number | ||
| Operator command | /oktaApprove |
Displays an Okta push request | ||
| Operator command | /oktaAuthApp |
Requests an Okta authenticator code | ||
| Operator command | /wrong2fa |
Rejects the current authentication code | ||
| Operator command | /done |
Completes the phishing flow | ||
| Operator command | /ban |
Suppresses the page for the visitor | ||
| GitHub repository | recruiterid/teslanewnewne |
Exposed recruitment frontend source | ||
| GitHub repository | recruiterid/newnewtesla |
Exposed recruitment backend source | ||
| GitHub account | reudisace |
Published related recruitment builds |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.