
An agency buyer reaches a page offering an AI assistant for ad campaigns and clicks Connect. A Google sign-in window appears. Its address looks right, yet nothing has opened at Google. In fact, the entire window, including its address bar, sits inside the phishing page.
An October 6 investigation traced this trick through fake portals branded as ChatGPT, Gemini, Claude and Perplexity. A newer page borrowed the name of Meta’s Muse assistant. Behind the polished screens, a human operator could request another password or switch to a multifactor prompt while attempting a real login. The investigation recorded hundreds of submissions, though the number of accounts accessed remains unknown.
There is no installer in this sequence. The bait is a business task that agency staff recognize, followed by a sign-in step that appears routine. That combination gives the operator both the first password and a chance to ask for the second factor at the right moment.
What is browser-in-the-browser phishing? It is a web page that paints a browser-like window inside the real tab. Its displayed address is part of the page, so it cannot verify the destination of the login form.
The Pitch Targets People Who Manage Ad Spend
The pages speak in the language of agency work. One fake ChatGPT service promises a Monday Google Ads briefing; a Gemini-themed page talks about linked client accounts. Another offers a Claude advertising portal. Each pitch gives the visitor a reason to connect a work account before asking for credentials.
The Muse variant shows how quickly the operators adapted. Meta announced its personal AI agent on September 8, 2026. By September 16, the phishing platform carried a counterfeit Muse Ads page promising sponsored placements and account connections. The invented advertising product used a fresh, legitimate name to make the request feel timely.
There is direct evidence for at least one email lure. A separate case documented a Gemini Ads beta invitation sent to a paid-media manager in late August. Its button pointed to an AI-styled connection page. That email establishes one route to a lure, although the wider set of pages may have reached visitors in other ways.
A False Address Bar Inside the Page
After the visitor presses Connect, the site draws what appears to be a Google login window. The imitation includes a lock icon and an address bar showing a trusted origin. Yet the outer browser never leaves the phishing page. The apparent provider address belongs to the page’s artwork, so it says nothing about where the form sends data.
Its window adapts to Windows, macOS, iOS and Android. Newer builds also mimic details such as Safari’s compact address display and a dark theme. Consequently, the page can match the visual habits of the device in front of it.
This mechanism differs from a live reverse proxy. The inspected platform rebuilds provider screens locally and collects entries through its own application. It supports Google, Meta, TikTok and Okta sign-in flows. Therefore, the operator can present several familiar authentication journeys without moving the visitor to those providers.
How Fake AI Ad Tools Target Google Accounts
The Operator Controls Each Authentication Step
Before the first credential appears, the application records the visitor’s browser and screen details. It also creates a live channel to the operator panel. Actions on the page travel back to that panel, and operator commands can change the next screen the visitor sees. The inspected code keeps up to three password attempts for one visitor.
That control matters when the operator tests a stolen password. If the real service asks for another factor, the fake page can show an SMS field, an authenticator prompt, a Google approval request or an Okta push request. A rejected code can lead to another prompt while the visitor waits. The operator chooses the sequence as the real sign-in unfolds.
So the page turns a familiar account-connection task into a conversation with the attacker. A fresh code may arrive just when the operator needs it. The published analysis documents these controls and observed submissions, but provides no verified total of successful sign-ins. A captured prompt does not, by itself, prove account access.
One Platform Serves Several Business Stories
AI-themed portals were one face of the same operation. The application also served Google Ads refund claims and recruitment pages. Under those different covers sat shared routes, operator commands and a Next.js and Socket.IO stack. The phishing team could change its pitch without discarding the machinery behind it.
Archived evidence reaches back before the current AI ads pages. Scans recorded 73 captures of 25 page domains from May 27 through June 20, 2026, all tied to one backend. The set included AI advertising lures, refund claims and a fake careers page. Those are observations of web pages, not a victim count.
Misconfigured public repositories exposed older recruitment code for comparison with newer advertising pages. Similar password-retry behavior and backend calls made the relationship clearer than the branding did. Together, the code and archived scans support platform reuse across several business stories; they do not establish who ran it.
A Manager Login Can Reach Beyond One Advertiser
An agency employee’s job matters as much as the false brand. Google Ads manager accounts let agencies work across several client accounts from one place. Access still depends on the user’s role and the manager account’s ownership of each client. A stolen login does not automatically grant every possible administrative action.
Still, a person with campaign-management rights can affect linked client campaigns. Administrative ownership can extend that reach to user access and account relationships. That makes an agency sign-in attractive even when the attacker has collected only one person’s credentials.
The published investigation did not identify a total for completed account takeovers, fraudulent ad spend or client losses. Its strongest finding is the operating method. A convincing product pitch brings the visitor to Connect, a fabricated window collects the login, and a person behind the panel steers the next authentication prompt in real time.
Conclusion: The Address Bar Was Fake. The Credentials Were Real.
The fake AI advertising portals demonstrate how attackers can steal business credentials without exploiting a vulnerability, installing malware, or compromising a legitimate authentication provider. By recreating familiar Google and other sign-in windows inside a phishing page, the operators turned an ordinary account-connection workflow into a credential-harvesting operation.
The deception begins before the login appears. Pages impersonating ChatGPT, Gemini, Claude, Perplexity, and Meta Muse offer services that advertising professionals might reasonably expect to use. Once the visitor clicks Connect, the page displays a convincing authentication window with a trusted-looking address bar. However, the real browser remains on the attacker’s domain, and the apparent security indicators are entirely controlled by the phishing page.
The operation becomes more dangerous when authentication requires additional verification. Rather than relying on a static form, a human operator can test submitted credentials against the legitimate service and request the appropriate MFA challenge in real time. The victim believes they are completing a normal authentication process while the attacker controls the sequence of prompts.
Investigators observed hundreds of credential submissions, but successful account takeovers and financial losses remain unconfirmed. The demonstrated capability is nevertheless significant, particularly when a single advertising account can provide access to multiple clients.
Why This Threat Matters
- A convincing address bar does not prove a legitimate connection. Browser-in-the-Browser attacks can reproduce familiar authentication windows, including trusted URLs and security indicators, entirely within a malicious page.
- MFA can become part of the deception. Operators can request passwords, verification codes, or authentication approvals while attempting to access the real service.
- Business context makes the lure credible. Advertising professionals are accustomed to connecting accounts, authorizing integrations, and working across multiple marketing platforms.
- One compromised identity can affect multiple clients. Agency manager accounts may provide access to several advertising environments, depending on the user’s permissions.
- The same phishing infrastructure can support multiple campaigns. Operators reused their platform across AI advertising services, refund claims, and recruitment lures while changing the branding presented to victims.
Where Defensive Control Must Operate
Xcitium Cyber Awareness Education helps employees recognize fabricated login windows, verify AI services through trusted channels, and question unexpected account-connection and MFA requests. Phishing Simulation tests whether users identify these deceptive interfaces and resist credential-harvesting attempts under realistic conditions.
When stolen credentials lead to unauthorized authentication, Xcitium ITDR provides an important additional layer for detecting suspicious sign-ins, abnormal identity activity, and unexpected privilege changes.
Verify the Real Browser, Not the Window Inside It
Organizations should treat requests to connect business accounts as security-sensitive actions, particularly when unfamiliar AI services or beta programs are involved. Employees must verify the actual browser address rather than trusting a URL displayed inside a webpage. Phishing-resistant authentication, restricted advertising-account privileges, and monitoring for unauthorized account changes further reduce the consequences when deception succeeds.