Cybersecurity researchers have uncovered a phishing operation that impersonates advertising platforms associated with ChatGPT, Google Gemini, Claude, Perplexity, Meta Muse and Manus. The fake services claim to help advertisers with campaign optimization, ad management and account connections, but are designed to steal login credentials and multi-factor authentication codes.
The campaign uses a Browser-in-the-Browser (BitB) technique, creating a fake login window inside the real browser. The counterfeit window can display trusted addresses such as accounts.google.com or an Okta login, making the phishing page appear legitimate. Attackers can then control the authentication flow and request additional passwords or MFA codes.
Researchers say the campaign specifically targets advertising agencies, media buyers and manager-account administrators, since compromised advertising accounts can be used to launch fraudulent campaigns or potentially sold to other criminals.
