Fake AI Ad Portals Put Business Logins in a False Window

Fake AI ad portals imitate ChatGPT, Gemini and Claude to capture business logins and MFA codes through a live, browser-in-the-browser phishing flow.

Protect the Identity Behind the Click
  • October 9, 2026

An agency buyer reaches a page offering an AI assistant for ad campaigns and clicks Connect. A Google sign-in window appears. Its address looks right, yet nothing has opened at Google. In fact, the entire window, including its address bar, sits inside the phishing page.

An October 6 investigation traced this trick through fake portals branded as ChatGPT, Gemini, Claude and Perplexity. A newer page borrowed the name of Meta’s Muse assistant. Behind the polished screens, a human operator could request another password or switch to a multifactor prompt while attempting a real login. The investigation recorded hundreds of submissions, though the number of accounts accessed remains unknown.

There is no installer in this sequence. The bait is a business task that agency staff recognize, followed by a sign-in step that appears routine. That combination gives the operator both the first password and a chance to ask for the second factor at the right moment.

What is browser-in-the-browser phishing? It is a web page that paints a browser-like window inside the real tab. Its displayed address is part of the page, so it cannot verify the destination of the login form.

The Pitch Targets People Who Manage Ad Spend

The pages speak in the language of agency work. One fake ChatGPT service promises a Monday Google Ads briefing; a Gemini-themed page talks about linked client accounts. Another offers a Claude advertising portal. Each pitch gives the visitor a reason to connect a work account before asking for credentials.

The Muse variant shows how quickly the operators adapted. Meta announced its personal AI agent on September 8, 2026. By September 16, the phishing platform carried a counterfeit Muse Ads page promising sponsored placements and account connections. The invented advertising product used a fresh, legitimate name to make the request feel timely.

There is direct evidence for at least one email lure. A separate case documented a Gemini Ads beta invitation sent to a paid-media manager in late August. Its button pointed to an AI-styled connection page. That email establishes one route to a lure, although the wider set of pages may have reached visitors in other ways.

A False Address Bar Inside the Page

After the visitor presses Connect, the site draws what appears to be a Google login window. The imitation includes a lock icon and an address bar showing a trusted origin. Yet the outer browser never leaves the phishing page. The apparent provider address belongs to the page’s artwork, so it says nothing about where the form sends data.

Its window adapts to Windows, macOS, iOS and Android. Newer builds also mimic details such as Safari’s compact address display and a dark theme. Consequently, the page can match the visual habits of the device in front of it.

This mechanism differs from a live reverse proxy. The inspected platform rebuilds provider screens locally and collects entries through its own application. It supports Google, Meta, TikTok and Okta sign-in flows. Therefore, the operator can present several familiar authentication journeys without moving the visitor to those providers.

How Fake AI Ad Tools Target Google Accounts

Cyber Attack Analysis: Fake AI Ads Portals Use Browser-in-the-Browser Phishing
Browser-in-the-Browser · AI Ad Lures
THE GOOGLE WINDOW LOOKED REAL.
It Was Drawn by the Phishing Page.

An agency buyer is offered an AI assistant for ad campaigns and clicks Connect. A familiar sign-in screen appears, complete with a trusted-looking address bar. But that address bar is only part of the page: the visitor never left the attacker’s site. No installer is needed; the lure is the work task and the account-connection step.

FOLLOW THE ATTACK
AI Campaign Assistant · Connect your ad account
Campaign workspace
Your Monday Ads Briefing
Connect a work account to review client campaigns, spot changes and prepare recommendations in one place.
Google Ads AI assistant
Connect Google account
Illustrative lure screen based on the reported campaign themes.
STEP 1: A BUSINESS TASK AS BAIT

The offer fits an agency buyer’s routine: connect an ad account to get campaign summaries or manage client accounts. Investigators found pages branded around ChatGPT, Gemini, Claude and Perplexity. One separate case documented a Gemini Ads beta invitation email; the pages may also have reached people through other routes.

campaign-connect[.]example
●●● accounts.google.com
Sign in with Google
Continue to AI Campaign Assistant
Email or phone
Next
This whole sign-in window is inside the page above.
STEP 2: BROWSER-IN-THE-BROWSER

The page draws a second, browser-like window inside the real tab. Its fake address bar can show a lock icon and a trusted Google address, but it is just artwork controlled by the phishing page. The outer browser remains on the attacker’s domain, and the form sends information to the phishing service.

Phishing page ⇄ operator panel
Fake sign-in page
Google · Meta · TikTok · Okta
Rebuilt provider screens
Visitor and screen details

live channel
Human operator
Sees the live flow
Chooses the next prompt
Tests the credentials
STEP 3: THE PAGE TALKS TO A PERSON

The inspected platform rebuilds provider screens locally and sends visitor activity to a live operator panel. It is not a reverse proxy that simply relays a real Google page. The same service supports Google, Meta, TikTok and Okta sign-in flows, letting the operator watch and steer what appears next.

One login attempt at a time
1Visitor enters an email and password into the fake provider screen.
2Operator tries the credentials against the real service while the visitor waits.
3If asked, the operator switches the fake page to an MFA step.
4A rejected code can lead to another prompt, chosen in real time.
Observed code supported up to three password attempts for one visitor.
STEP 4: MFA BECOMES A LIVE CONVERSATION

The operator can request another password or switch to an SMS code, authenticator code, Google approval or Okta push prompt, depending on the real login. If a factor fails, another prompt may appear while the operator tests the next step. The victim sees a familiar sign-in flow; the attacker is directing it.

Agency account → client campaigns
Agency buyer’s Google Ads access
access depends on assigned role and ownership

Client A
campaigns

Client B
campaigns

Client C
campaigns
STEP 5: ONE WORK LOGIN, SEVERAL CLIENTS

An agency manager account can connect staff to multiple advertisers, which makes an agency employee’s sign-in valuable. A compromised user may be able to change campaigns for linked clients. The actual reach depends on that user’s role and the manager account’s ownership; one stolen login does not automatically grant every administrative action.

Evidence and limits

Observed submissions

The investigation recorded hundreds of credential submissions to the platform.

Not confirmed

How many accounts were successfully accessed, how much ad spend was affected, and whether clients suffered losses.

Historic captures

73 archived captures across 25 page domains, May 27–June 20, 2026, tied to one backend.

A submitted password or MFA response is evidence of collection. By itself, it does not prove that the operator completed a sign-in.

STEP 6: COLLECTION IS NOT PROOF OF TAKEOVER

Investigators recorded hundreds of submissions, but how many accounts were accessed remains unknown. The archive held 73 page captures across 25 domains; that is not a count of confirmed victims. No account takeovers, fraudulent spend or client losses were verified.

Different landing pages · Shared backend
AI advertising assistants
Google Ads refund claims
Recruitment pages
Shared application routes and operator controls
Meta announced Muse on September 8, 2026; investigators saw a counterfeit Muse Ads page by September 16. Older recruitment code found in exposed public repositories helped compare the reused behavior. Shared code and infrastructure support a finding of platform reuse; they do not identify who operated it.
STEP 7: THE BRAND CHANGES; THE KIT REMAINS

AI ad portals were one cover. Operators also used the same Next.js and Socket.IO application for refund and recruitment lures. A counterfeit Muse Ads page appeared by September 16, eight days after Meta announced Muse, showing how quickly the pitch could adapt. Shared infrastructure points to platform reuse, but does not identify who operated it.

RECOMMENDED ACTIONS
Pause Before You Connect a Work Account

Treat an unexpected AI tool or beta invitation as an untrusted request for account access. Verify the product through a known vendor channel, inspect the real browser address bar, and never treat an address drawn inside a page as proof that Google or another provider is handling the sign-in.

The Operator Controls Each Authentication Step

Before the first credential appears, the application records the visitor’s browser and screen details. It also creates a live channel to the operator panel. Actions on the page travel back to that panel, and operator commands can change the next screen the visitor sees. The inspected code keeps up to three password attempts for one visitor.

That control matters when the operator tests a stolen password. If the real service asks for another factor, the fake page can show an SMS field, an authenticator prompt, a Google approval request or an Okta push request. A rejected code can lead to another prompt while the visitor waits. The operator chooses the sequence as the real sign-in unfolds.

So the page turns a familiar account-connection task into a conversation with the attacker. A fresh code may arrive just when the operator needs it. The published analysis documents these controls and observed submissions, but provides no verified total of successful sign-ins. A captured prompt does not, by itself, prove account access.

One Platform Serves Several Business Stories

AI-themed portals were one face of the same operation. The application also served Google Ads refund claims and recruitment pages. Under those different covers sat shared routes, operator commands and a Next.js and Socket.IO stack. The phishing team could change its pitch without discarding the machinery behind it.

Archived evidence reaches back before the current AI ads pages. Scans recorded 73 captures of 25 page domains from May 27 through June 20, 2026, all tied to one backend. The set included AI advertising lures, refund claims and a fake careers page. Those are observations of web pages, not a victim count.

Misconfigured public repositories exposed older recruitment code for comparison with newer advertising pages. Similar password-retry behavior and backend calls made the relationship clearer than the branding did. Together, the code and archived scans support platform reuse across several business stories; they do not establish who ran it.

A Manager Login Can Reach Beyond One Advertiser

An agency employee’s job matters as much as the false brand. Google Ads manager accounts let agencies work across several client accounts from one place. Access still depends on the user’s role and the manager account’s ownership of each client. A stolen login does not automatically grant every possible administrative action.

Still, a person with campaign-management rights can affect linked client campaigns. Administrative ownership can extend that reach to user access and account relationships. That makes an agency sign-in attractive even when the attacker has collected only one person’s credentials.

The published investigation did not identify a total for completed account takeovers, fraudulent ad spend or client losses. Its strongest finding is the operating method. A convincing product pitch brings the visitor to Connect, a fabricated window collects the login, and a person behind the panel steers the next authentication prompt in real time.

Conclusion: The Address Bar Was Fake. The Credentials Were Real.

The fake AI advertising portals demonstrate how attackers can steal business credentials without exploiting a vulnerability, installing malware, or compromising a legitimate authentication provider. By recreating familiar Google and other sign-in windows inside a phishing page, the operators turned an ordinary account-connection workflow into a credential-harvesting operation.

The deception begins before the login appears. Pages impersonating ChatGPT, Gemini, Claude, Perplexity, and Meta Muse offer services that advertising professionals might reasonably expect to use. Once the visitor clicks Connect, the page displays a convincing authentication window with a trusted-looking address bar. However, the real browser remains on the attacker’s domain, and the apparent security indicators are entirely controlled by the phishing page.

The operation becomes more dangerous when authentication requires additional verification. Rather than relying on a static form, a human operator can test submitted credentials against the legitimate service and request the appropriate MFA challenge in real time. The victim believes they are completing a normal authentication process while the attacker controls the sequence of prompts.

Investigators observed hundreds of credential submissions, but successful account takeovers and financial losses remain unconfirmed. The demonstrated capability is nevertheless significant, particularly when a single advertising account can provide access to multiple clients.

Why This Threat Matters

  • A convincing address bar does not prove a legitimate connection. Browser-in-the-Browser attacks can reproduce familiar authentication windows, including trusted URLs and security indicators, entirely within a malicious page.
  • MFA can become part of the deception. Operators can request passwords, verification codes, or authentication approvals while attempting to access the real service.
  • Business context makes the lure credible. Advertising professionals are accustomed to connecting accounts, authorizing integrations, and working across multiple marketing platforms.
  • One compromised identity can affect multiple clients. Agency manager accounts may provide access to several advertising environments, depending on the user’s permissions.
  • The same phishing infrastructure can support multiple campaigns. Operators reused their platform across AI advertising services, refund claims, and recruitment lures while changing the branding presented to victims.

Where Defensive Control Must Operate

Xcitium Cyber Awareness Education helps employees recognize fabricated login windows, verify AI services through trusted channels, and question unexpected account-connection and MFA requests. Phishing Simulation tests whether users identify these deceptive interfaces and resist credential-harvesting attempts under realistic conditions.

When stolen credentials lead to unauthorized authentication, Xcitium ITDR provides an important additional layer for detecting suspicious sign-ins, abnormal identity activity, and unexpected privilege changes.

Verify the Real Browser, Not the Window Inside It

Organizations should treat requests to connect business accounts as security-sensitive actions, particularly when unfamiliar AI services or beta programs are involved. Employees must verify the actual browser address rather than trusting a URL displayed inside a webpage. Phishing-resistant authentication, restricted advertising-account privileges, and monitoring for unauthorized account changes further reduce the consequences when deception succeeds.

Like what you see? Share with a friend.

Move Away From Detection With Patented Threat Prevention Built For Today's Challenges.

No one can stop zero-day malware from entering your network, but Xcitium can prevent if from causing any damage. Zero infection. Zero damage.

Book a Demo