As reported by BleepingComputer, threat actors are weaponizing the current AI hype cycle — impersonating ChatGPT, Gemini, Claude, Perplexity, and Meta's Muse AI to phish advertising account credentials and MFA codes via browser-in-the-browser (BitB) attacks. This campaign deserves more attention than a typical phishing alert because it signals a deliberate shift in targeting toward high-value, multi-tenant advertising accounts.

Threat Alert: As reported by BleepingComputer, threat actors are weaponizing the current AI hype cycle — impersonating ChatGPT, Gemini, Claude, Perplexity, and Meta's Muse AI to phish advertising account credentials and MFA codes via browser-in-the-browser (BitB) attacks.

Why advertising accounts, and why now?

The targeting is not accidental. Agency media buyers and ad administrators typically manage dozens or hundreds of downstream client accounts — each carrying spend balances, stored payment instruments, and the ability to push campaigns to millions of viewers. A single compromised operator account can yield fraud proceeds that dwarf what a stolen consumer email would fetch on dark-net markets. Stolen ad inventory is also being resold to other criminals, creating a secondary economy that incentivizes continued investment in lures and human operators.

The use of AI-branded lures is a clever social-engineering multiplier. After 18 months of AI product launches, advertisers are actively seeking automation tools that promise efficiency in campaign planning, auditing, and audience targeting. The fake 'Muse AI' branding borrows legitimacy from Meta's real agent, lowering the skepticism of media buyers who already expect to authenticate with Google or SSO when onboarding new SaaS.

BitB defeats naive MFA training

The browser-in-the-browser technique, originally demonstrated by researcher mr.dox in 2022, remains one of the most effective MFA-bypass vectors because it defeats the most common user education heuristic: 'check the URL.' Inside the fraudulent pop-up, the attacker renders a fake address bar displaying the expected domain — accounts.google.com, in this case — so users who were trained to verify URLs are reassured rather than alarmed.

BitB exploits a fundamental gap in browser UX: users trust the contents of a pop-up window because they trust the parent page. When the parent page is already malicious, that trust transfers to the attacker.

What makes this campaign particularly dangerous is the live human operator in the loop. Unlike automated phishing kits that fail at the first unexpected prompt, these operators can ask for credentials multiple times, trigger Okta push requests, display QR codes, suppress or reject codes, and hold victims in waiting screens — adapting in real time to each victim's MFA posture.

Infrastructure tells a bigger story

The shared infrastructure — Next.js and Socket.IO stacks on Vercel, Railway, and Render backends — suggests a single, well-resourced threat group running multiple lures (recruitment scams, refund pages, AI product phishing) from common components. That's a production-grade criminal operation, not a lone actor.

Shield53 Recommendations

  • Enforce hardware-backed MFA on all ad and SSO accounts. Phishing-resistant MFA (FIDO2/WebAuthn security keys or platform authenticators with device-bound credentials) cannot be relayed or replayed by a live operator. SMS, TOTP, and even Okta push are all bypassable here.
  • Restrict ad account access by IP and device posture. Advertising platforms that support allowlisting of management IPs or managed-device policies should be configured. Conditional access that blocks logins from unfamiliar ASNs is effective against relayed credential use.
  • Deploy anti-BitB browser controls. Modern managed browsers can disable or alert on pop-ups, cross-origin iframe embedding of login flows, and credential autofill into non-verified origins. Review your EPM/browser isolation policy.
  • Train staff on the 'connect account' lure specifically. Generic phishing training misses this. Teach media buyers that no legitimate AI tool — including Meta's Muse — requires them to 'connect' their Google ad account through an embedded pop-up. Real OAuth flows open in the native browser or OS, not an in-page window.
  • Monitor for Vercel/Render-hosted lookalikes. Threat intelligence teams should flag newly registered subdomains on .vercel.app, .onrender.com, and .railway.app that spoof AI brands, and feed indicators to DNS filtering and email security gateways.
  • Segment ad account roles. Limit how many operators hold admin-level access across multiple client accounts. The blast radius of one compromised operator should never be 'every client we manage.'

The convergence of AI-brand phishing, BitB MFA bypass, and high-value ad-account targeting is a preview of where credential theft is heading. Defenders who still treat MFA as a finish line rather than a layer will learn this lesson the expensive way.