Phishing Kit Spoofs AI Ad Portals to Steal Credentials — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Island researchers Oleg Zaytsev and Ofek Ronen disclosed a phishing kit impersonating ad-management portals for ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus, each with its own brand pitch and sign-in flow built around a single "Connect" call to action.
- The platform uses a browser-in-the-browser (BitB) overlay to display trusted URLs like accounts.google.com or Okta tenants while actually running on the attacker's domain, fingerprinting devices and relaying data to an "/api/send/ip" endpoint over Socket.IO.
- Operators steer victims through authentication in real time via Socket.IO events ("operator-command" and "telegram-command"), selecting MFA challenges such as SMS (/2fa), authenticator (/authApp), Google prompts (/googlePrompt), or Okta push (/oktaApprove) and even rejecting bad codes with /wrong2fa.
- The site museads.ai appeared on September 16, 2026 — roughly a week after Meta's Muse launch — and targeted Google, Meta, TikTok, and Okta credentials from media buyers and manager-account administrators likely chosen so attackers can monetize clean ad accounts.
- The AI-ads prong is part of a larger three-pronged phishing platform that also includes Google Ads-themed refund/payment pages and recruitment-themed lures impersonating Tesla, Louis Vuitton, Nike, and Adecco, all sharing a Next.js + Socket.IO stack and common endpoints.
- Threat actors inadvertently exposed earlier versions of the platform's source code through misconfigured public GitHub repositories, giving researchers direct visibility into the command schema and victim-tracking logic.
- In a related finding, Island separately reported that attackers are abusing Google-sponsored search results to funnel users to attacker-authored ChatGPT or Gemini content that redirects to fake Cloudflare verification pages delivering the NetSupport RAT via ClickFix lures.
Why it matters: Account recovery for stolen ad manager accounts typically takes weeks or months while ads keep running, meaning a single compromised login at an agency can cascade into client budgets — and the attackers are betting on AI-brand trust and real-time MFA manipulation to make those compromises stick.
Ask SkimNews


