A phishing campaign is targeting ad account managers with fake ChatGPT, Gemini, Claude, Perplexity, and Muse AI pages that steal credentials and MFA codes through browser-in-the-browser attacks. The operation also appears tied to a broader scheme using fake recruitment and refund lures, with infrastructure traced through exposed GitHub repositories and control channels receiving hundreds of victim submissions. #ChatGPT #Gemini #Claude #Perplexity #MuseAI #Island
Keypoints
- Fake AI sites lure ad account managers into entering credentials and MFA codes.
- The campaign uses browser-in-the-browser phishing to fake Google login windows.
- Victims include agency staff, media buyers, and administrators with access to downstream clients.
- Attackers can spend ad balances or resell compromised accounts to other criminals.
- The operation is linked to a broader infrastructure using fake recruitment and refund pages.