As reported by The Hacker News, security researchers at Island have uncovered a sophisticated human-operated phishing campaign that impersonates advertising products for major AI chatbot brands — including Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The campaign is notable not just for its breadth, but for its operational sophistication: it combines browser-in-the-browser (BitB) spoofing, real-time operator interaction, device fingerprinting, and dynamic MFA challenge manipulation into a single credential-harvesting pipeline.
Why This Campaign Demands Attention
This isn't garden-variety phishing. The platform is human-operated, meaning a live attacker adapts the MFA challenge presented to each victim based on their target account's actual authentication flow. That changes the defensive calculus significantly — static detection rules looking for fixed MFA prompt patterns will fail because the attacker mirrors whatever the legitimate IdP would present.
The BitB technique is particularly effective here because the victim's real browser stays on the phishing domain while a fake browser window is drawn on top, displaying a spoofed address bar pointing to trusted origins like accounts.google.com. Even security-conscious users who verify URLs can be fooled, because the fake address bar is rendered by the attacker's JavaScript, not the browser's native chrome.
Who Is at Risk
Broader Implications: AI Branding as a Trust Vector
The most significant takeaway is how quickly threat actors are capitalizing on AI product launches. The museads.ai domain appeared just days after Meta launched Muse. This pattern signals that threat actors are monitoring AI product announcements and rapidly standing up themed infrastructure to exploit the window of user unfamiliarity that accompanies new product launches.
As AI tools become embedded in enterprise workflows, employees increasingly expect to authenticate to unfamiliar AI-adjacent services. This normalizes the exact behavior attackers need — clicking a link, signing into what appears to be a new AI tool, and approving an MFA prompt. The AI gold rush is creating a phishing surface faster than organizations can educate users about it.
Shield53 Recommendations
Immediate Actions
- Block known indicators: Add
museads.aiand associated Socket.IO endpoints to network and web proxy blocklists. Monitor for outbound connections to/api/send/ippaths over WebSocket protocols. - Alert on BitB signatures: Deploy detection rules for browser-in-the-browser patterns — specifically, pop-up windows containing address bar elements rendered via DOM manipulation rather than native browser APIs.
- Enforce FIDO2 hardware keys: For Okta and Google Workspace admins, require phishing-resistant MFA (FIDO2/WebAuthn). TOTP and push-based MFA are vulnerable to the real-time relay this platform performs.
- Restrict new AI SaaS sign-ups: Implement procurement and IT approval workflows for new AI tool subscriptions. No employee should be able to authenticate to an unsanctioned AI advertising platform without verification.
Strategic Defenses
- Train on BitB specifically: Standard phishing training doesn't cover browser-in-the-browser. Update awareness programs to demonstrate this technique and teach users to look for the real browser's address bar, not the spoofed one.
- Monitor OAuth grant activity: If the attacker obtains session tokens, they may establish OAuth app grants for persistence. Audit consent grants in Google Workspace and Okta regularly.
- Threat-hunt for session anomalies: Look for impossible travel, unusual IP geolocation, and new device fingerprints on accounts that recently accessed AI-related domains.
The window between a major AI product launch and the appearance of themed phishing infrastructure is narrowing to days, not weeks. Organizations must treat any unsolicited AI tool invitation — especially one requiring authentication — as high-risk until independently verified.
Shield53 assesses that this campaign will likely expand to additional AI brands as threat actors iterate on its success. The combination of brand novelty, human-operated MFA handling, and BitB visual deception represents a maturation of credential phishing that demands phishing-resistant authentication as a baseline, not an enhancement.