
Researchers at browser security company Island describe a phishing campaign aimed at people who manage online advertising accounts: agency staff, media buyers and administrators whose logins reach many clients’ accounts. The lures are fake sites posing as ChatGPT, Gemini, Claude and Perplexity tools that promise to help plan and audit ad campaigns, and they leaned on the recent launch of Meta’s Muse AI agent. To use the tool, the visitor is asked to “connect” an account.
The Connect button opens what looks like a Google sign-in pop-up, address bar showing accounts.google.com included. It is a browser-in-the-browser (BitB) fake: an iframe drawn inside the page to look like a separate browser window. A human operator then drives the session, asking for the password up to three times and for SMS or authenticator codes, or showing Okta push requests, Google approval prompts or QR codes. Operators can also reject codes and hold victims on a waiting screen. The kit also supports Meta, TikTok and Okta sign-ins. Island says the operation reaches back to March, uses lures such as fake job offers and refund pages, and exposed older source code in public GitHub repositories. The attackers’ Telegram channel had received hundreds of victim submissions, though that does not equal the number of accounts actually taken over. Stolen ad accounts can be used to spend balances on fraudulent ads or be resold.
How to check if you’re affected
Affected products are Google, Meta, TikTok and Okta sign-ins for advertising and agency accounts, if you entered credentials or codes after clicking Connect on an AI “ad assistant” site. If you did:
- Change the password for the account you entered, and for any other account that reuses it, from a different device.
- Sign out all active sessions and review recent sign-ins, connected apps and any new users or payment methods on your ad accounts.
- Re-enroll MFA and review ad spend and billing for charges you did not make.
To spot the trick, try dragging the “pop-up” outside the main browser window or resizing it. A real OAuth window can move and resize independently; a BitB fake is stuck inside the page. Only connect AI tools you reached from the vendor’s own site.
