VMTech
Discuss a project →

Fake AI advertising portals use BitB to steal business logins

Fake AI advertising portals use BitB to steal business logins

Island researchers have identified a human-operated phishing platform that imitates advertising products for AI chatbot brands including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse and Manus. The operation is built to collect business credentials and multi-factor authentication codes through spoofed sign-in windows.

The pages claim to provide campaign optimisation, spend audits and business-account connections. Their central call to action is typically a “Connect” button, but activating it opens a browser-in-the-browser, or BitB, window rather than a legitimate authentication flow.

Trusted-looking windows conceal the phishing domain

Island researchers Oleg Zaytsev and Ofek Ronen said the fake window is drawn inside the victim’s real browser. It can display an address bar showing a trusted origin, such as accounts.google.com or an Okta tenant, while the actual browser remains on the phishing site.

One observed site, museads.ai, appeared on September 16, 2026, shortly after Meta introduced Muse, its AI agent for personal workflows. Styled as an AI ads manager for paid-media workflows, it offered connections for Google, Meta, TikTok and Okta accounts. Its prompt box and Connect button instead triggered a credential-harvesting BitB flow.

Behind the interface, the platform fingerprints the device and sends information to an attacker-controlled /api/send/ip endpoint over Socket.IO. Operator commands and victim data are then exchanged according to the selected login workflow. The platform records password attempts and allows an operator to choose which MFA challenge appears next, while attempting to sign in to the targeted account in real time.

Distinct brand pitches point to one shared operation

The phishing sites use tailored sales messages to make each impersonation appear credible. ChatGPT-themed pages promise a Monday Google Ads brief; Gemini-themed pages advertise manager-account and linked-client support; Claude has a dedicated advertising portal; Perplexity promotes campaign planning and spend audits; and Manus presents a private Meta integration.

Island assessed that fake invitation emails impersonating the trusted brands direct recipients to the landing pages. The AI advertising cluster is part of a wider three-pronged platform that also includes Google Ads refund and payment-confirmation lures, plus recruitment-themed sites impersonating Tesla, Louis Vuitton, Nike and Adecco.

All identified sites share a technology stack based on Next.js and Socket.IO and communicate with the same endpoints. Island also found that earlier versions of the platform had source code exposed through misconfigured public GitHub repositories.

Advertising accounts are a high-value target

The campaign appears aimed at agency staff, media buyers and manager-account administrators. Attackers may seek to use compromised accounts for their own advertising or sell accounts with clean spending histories. Island warned that removing a payment card can be relatively quick, but restoring control is harder when attackers add their own administrators and downgrade the legitimate owner.

For manager accounts, the consequences can extend to an agency’s clients and recovery may take weeks or months while ads continue to run. Businesses should deploy phishing-resistant authentication, monitor changes to advertising controls and administrators, and assess AI integrations carefully before granting access to advertising accounts.

#cybersecurity#phishing#accountsecurity#aiads
Open analytics
On the site 0 views
min read 4 06.10.2026
Instagram

Fake AI advertising portals use BitB to steal business logins

Open the post on Instagram ↗