Phishing Platform Mimics AI Ads to Harvest Credentials
π Cybersecurity researchers disclosed a human-operated phishing platform impersonating AI ad products like Google Gemini, Anthropic Claude, and OpenAI ChatGPT. The sites lure targets with ad-management pitches and use a browser-in-the-browser (BitB) trick to present spoofed login windows that capture credentials and MFA codes. Operators fingerprint devices, relay victim inputs over Socket.IO, and select subsequent MFA challenges to complete account takeovers. The campaign surfaced pages such as museads.ai and leverages fake invitation emails, shared technology stacks, and misconfigured GitHub repos to scale attacks.
