The images in this article were generated with artificial intelligence. How we publish
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA assistants - including Google Gemini, ChatGPT, Claude, Perplexity, Muse and Manus - with the main objective of collecting credentials and multi-factor authentication codes (MFA). According to the report shared by analysts, fraudulent sites promise services such as campaign optimization, expenditure audits and corporate account connections, and use a visual deception known as "browser-in-the-browser" (BitB) to show fake login windows that appear to belong to legitimate domains while the real browser remains on the fraudulent page.
Facts confirmed by researchers: the fraudulent pages included in the analysis share the same technical stack (Next.js and Socket.IO), use a flow in which a "Connect" button opens a drunk interface that simulates a trusted address bar and captures password attempts. In parallel a fingerprint of the device is recorded and the platform transmits data to the operator by calls to endpoints such as "/ api / send / ip" and real-time communication by Socket.IO. Operators address what MFA challenge is shown to the victim and can try to log into the target account in real time with the credentials obtained. The researchers also reported that some domains (for example, museads.ai) appeared shortly after the public launch of certain IA products, and that the same infrastructure supported other phishing themes (Google Ads reimbursement claims, payment confirmations and false job offers for known brands). In addition, the research points out that earlier versions of the platform code were exposed in poorly configured public repositories.

Technically, the BitB deception exploits the user's visual confidence: instead of redirecting to an external page, the attacker draws a browser window within the legitimate page that includes a false address bar with recognizable URL. If the victim enters user, password and MFA code into that box, the operator receives that entry and can use it immediately to access it from its own browser. The use of Socket.IO facilitates real-time bidirectional communication between the victim and the operator, allowing the attacker to adapt the flow (e.g., request a code for SMS, app or key) as appropriate. The fingerprinting collects signals from the device that help operators to avoid security controls or to select the most effective authentication method.
Who does this affect? Mainly staff with administrative or account management access: agency managers, media buyers and account managers manager (MCC). The interest of the attacker is usually economic: an advertising account with a clean record and billing permits is valuable because it allows you to launch campaigns with stolen cards or insert payments that the attacker can then monetize or sell in illicit markets. In addition, when an account manager is compromised, the damage is spread to customers and related accounts, complicating recovery.
Real and practical consequences: Although a victim can remove a payment card in hours, recovering effective control of an advertising account may take weeks or months. The attackers often add their own administrators, degrade the legitimate owner's permissions or keep campaigns going while the recovery is negotiated, generating invoices for fraudulent expenses and loss of reputation for the agency and its customers. In similar cases, malware has been used to steal access and data, and actors have taken advantage of sponsored results and shared content on search platforms and chat to direct traffic to these scams.
Information reported vs. uncertain aspects: the technical details described and the existence of specific domains are reported by the researchers and are documented in their report. The economic motivations and the estimate that the attackers will sell accounts or use them to spend fraudulently are plausible and supported by previous investigations into the theft of advertising accounts, but the identity of the operators, their total scope and the exact sum of the money disappointed in these incidents were not publicly confirmed and remain uncertain.
Specific actions to be taken by readers and organizations: first, assume that login in ad management contexts are among the most valuable vectors and act accordingly. Practical and applicable recommendations today:
1) Migrate to phishing-resistant authentication. Implement physical safety keys or passwords (WebAuthn / FIDO2) for privileged accounts. The physical keys prevent a false window from capturing usable data. Guidelines and standards on this approach are available in NIST and FIDO Alliance documentation: NIST SP 800-63B and FIDO Alliance - how it works.
2) Segment access and reduce privileges. Do not use personal accounts with administrative permits; use accounts with minimum roles for daily tasks. Set up alerts on advertising platforms for billing changes, added administrators and campaigns with unusual expense.
3) Protect the phishing surface. Implement DNS / HTTP blocks to suspicious URL domains and patterns through network security solutions, and use mail policies (SPF / DKIM / DMARC) and filtering tools to reduce false invitations to staff.

4) Context verification and operational procedures. For connections to third party accounts or integrations, require off-band steps (call, check with secondary administrator) before accepting sensitive changes. Teach how to identify soft windows vs. real windows and to check that the full URL in the real browser bar corresponds to the desired entity.
5) Response to commitment. If you suspect engagement, revoke sessions and tokens, change passwords with phishing-resistant mechanisms, remove unknown administrators and immediately contact the platform support to request freeze account and review charges. Notify the bank and enable cash disputes where appropriate.
Finally, prevention requires coordination between computer security, marketing equipment and ad providers. The research that documents these tactics underlines that attackers no longer depend only on technical vulnerabilities: are exploiting brand confidence and media today to mask sophisticated fraud. Organizations with responsibility for advertising accounts should prioritize the adoption of phishing-resistant MFA, strict access controls and verification procedures for any third-party connection. To better understand the phenomenon of phishing and basic defensive techniques, the resources of the phishing community are a good starting point: OWASP - Phishing.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...