Executive Summary
In October 2026, cybercriminals launched a sophisticated phishing campaign targeting advertising account managers using fake AI assistant sites impersonating ChatGPT, Gemini, Claude, and Perplexity. The attackers leveraged browser-in-browser (BitB) attacks to steal login credentials and multi-factor authentication codes from agency staff and media buyers with access to multiple client accounts. The campaign exploited Meta's recent Muse AI agent launch as a lure, with human operators dynamically controlling the phishing flow to bypass MFA protections and potentially compromise hundreds of high-value advertising accounts.
This incident highlights the escalating threat of AI-themed phishing attacks as cybercriminals exploit the rapid adoption of AI tools in business workflows. The campaign's sophisticated use of real-time operator control and adaptive interfaces across multiple platforms demonstrates how threat actors are evolving their tactics to target high-value accounts with significant financial exposure.
Why This Matters Now
AI-themed phishing attacks are surging as organizations rapidly adopt AI tools without adequate security controls, creating new attack vectors that bypass traditional security awareness training and exploit trust in legitimate AI platforms.
Attack Path Analysis
Attackers deployed fake AI platforms (ChatGPT, Gemini, Claude) to phish advertising account credentials through browser-in-browser attacks, bypassing MFA to gain initial access. Once authenticated, they likely escalated privileges within advertising platforms to access multiple client accounts. Lateral movement occurred across connected advertising accounts and client environments. Command and control was established through Socket.IO and Telegram channels for real-time victim interaction. Exfiltration focused on stealing credentials, MFA codes, and advertising account data. Impact included fraudulent ad spending and account resale to other cybercriminals.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers created fake AI platforms mimicking ChatGPT, Gemini, Claude, and Perplexity to target advertising account managers through browser-in-browser phishing attacks that steal credentials and MFA codes
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Steal Web Session Cookie
Modify Authentication Process: Hybrid Identity
Multi-Factor Authentication Request Generation
Browser Session Hijacking
Acquire Infrastructure: Domains
Stage Capabilities: Link Target
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication Implementation
Control ID: 8.2.1
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
CISA ZTMM 2.0 – Enterprise Manages and Identifies All Enterprise Users
Control ID: Identity-1
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Information Security Awareness, Education and Training
Control ID: A.7.2.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Marketing/Advertising/Sales
Direct targeting of ad account managers through fake AI tools compromises campaign budgets, client data, and multi-factor authentication systems via browser-in-browser attacks.
Information Technology/IT
Browser-in-browser phishing exploits web application vulnerabilities, bypassing MFA protections and requiring enhanced egress security controls and anomaly detection capabilities.
Financial Services
Credential theft enabling fraudulent ad spending and account resale threatens financial controls, requiring zero trust segmentation and encrypted traffic monitoring.
Computer Software/Engineering
Exposed GitHub repositories reveal attack infrastructure, highlighting need for secure development practices and multicloud visibility to prevent similar credential harvesting campaigns.
Sources
- Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codeshttps://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/Verified
- Behind the Connect Button: The Fake AI Ads Campaignhttps://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaignVerified
- New phishing toolkit lets anyone create fake Chrome browser windowshttps://www.bleepingcomputer.com/news/security/new-phishing-toolkit-lets-anyone-create-fake-chrome-browser-windows/Verified
- Browser-in-the-browser attacks target CS2 players' Steam accountshttps://www.bleepingcomputer.com/news/security/browser-in-the-browser-attacks-target-cs2-players-steam-accounts/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of this advertising account compromise by constraining lateral movement and limiting outbound data paths. Segmented access controls could have reduced attacker reach across connected client environments and advertising platforms.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: CNSF visibility may have detected anomalous authentication patterns and connections from compromised accounts to cloud advertising platforms, potentially flagging suspicious access behaviors early in the attack sequence.
Control: Zero Trust Segmentation
Mitigation: Identity-aware segmentation policies would likely have constrained the scope of privilege escalation by limiting access to administrative functions based on user identity and context, reducing the attacker's ability to reach multiple client accounts.
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely have limited lateral movement between advertising accounts and client environments, constraining the attacker's ability to access connected cloud services and downstream client infrastructure.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility across cloud environments may have detected suspicious outbound connections to external command and control infrastructure, potentially identifying Socket.IO and Telegram communication channels used by attackers.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have restricted unauthorized data flows from advertising platforms to external destinations, potentially limiting the volume of credentials and account data successfully exfiltrated to attacker infrastructure.
While fraudulent spending may still occur on initially compromised accounts, the reduced blast radius from segmentation controls would likely limit the number of affected client accounts and constrain the overall financial impact.
Impact at a Glance
Affected Business Functions
- Digital Advertising Operations
- Client Account Management
- Media Buying and Planning
- Campaign Budget Administration
Estimated downtime: 3 days
Estimated loss: N/A
Compromised advertising account credentials, multi-factor authentication codes, OAuth tokens for Google, Meta, TikTok, and Okta platforms. Potential unauthorized access to client advertising budgets and campaign data across multiple downstream accounts managed by advertising agencies and media buyers.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to limit lateral movement between advertising accounts and client environments using identity-based policies and microsegmentation
- • Deploy Egress Security & Policy Enforcement to detect and block unauthorized data exfiltration attempts to external destinations like Telegram channels
- • Enable Multicloud Visibility & Control to detect anomalous interactions with fake AI platforms and suspicious automation patterns in advertising workflows
- • Utilize Threat Detection & Anomaly Response capabilities to baseline normal advertising platform behavior and alert on credential theft indicators
- • Enforce Cloud Native Security Fabric controls to inspect and block browser-in-browser attacks and validate legitimate OAuth flows in real-time



