Categories
Ace Security Desk

Hackers Use Fake ChatGPT, Claude & Gemini Ads to Steal Passwords & MFA Codes

Ace Security Desk – Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes according to Cybersecurity by Published: Oct.07: 2026

Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes

Instead of delivering a conventional malware download, the campaign uses convincing websites and live human operators to guide victims through fraudulent sign-in screens.

Invitation emails lead advertisers to pages promising campaign planning, spending audits and account connections. The approach echoes earlier attacks involving fake AI advertising apps, which used familiar technology brands to make credential requests appear legitimate.

Island.io researchers Oleg Zaytsev and Ofek Ronen identified the operation and observed hundreds of victim submissions, with activity continuing when their findings were published on October 6, 2026. 

Island.io said in a report shared with Cyber Security News (CSN) that attackers could reject passwords, select authentication challenges and redirect victims after completing the flow.

Victim data and operator commands (Source - Island.io)
Victim data and operator commands (Source – Island.io)

The campaign targets agency employees, media buyers and advertising account administrators. A single compromised manager account can expose several clients, their billing profiles and approved advertising budgets, turning an apparently routine integration request into a potentially expensive business incident.

Hackers Use Fake ChatGPT, Claude and Gemini Ads

Each fake product offers a tailored reason to connect an account. ChatGPT impersonations promise a weekly Google Ads briefing, Gemini pages advertise manager-account support, and Claude receives its own advertising portal. 

Perplexity and Manus branding also appear across the operation. The newest lure, Muse Ads, appeared by September 16, eight days after Meta announced Muse. 

Researchers found that its sign-in forms and fake browser window reused the wider platform’s existing code, showing how quickly operators could attach a new product story to established infrastructure.

Clicking Connect does not open a genuine Google authentication window. Instead, the website draws a second browser inside the real one, using the browser within browser technique to display a convincing address bar and lock icon while the actual page remains on attacker-controlled infrastructure.

The imitation adjusts to Windows, macOS, iOS and Android. Newer versions reproduce details such as dark mode, mobile browser controls and translucent toolbars. These touches make the false window look familiar without changing the real browser’s address or origin.

Behind that interface, the platform records device characteristics, location and submitted credentials. It preserves three separate password attempts, allowing an operator to claim that an entry failed, request another and retain every value the victim provides.

Human operators then choose the next authentication step while attempting the real login. Supported prompts include text-message codes, authenticator codes, Google approvals, QR verification, number matching and Okta push requests. A waiting screen keeps victims engaged while the attacker decides what to request next.

Shared Infrastructure and Account Protection

The same Next.js and Socket.IO platform supports AI advertising pages, refund claims and fake recruitment sites. Researchers linked one backend to 73 archived scans covering 25 page domains between May 27 and June 20, connecting apparently unrelated lures through shared infrastructure.

Older source code exposed through public GitHub repositories revealed matching routes, the three-password retry model and Telegram-based controls. 

The visible platform rebuilds login interfaces locally rather than transparently forwarding an identity provider’s website, making its traffic resemble ordinary application activity.

Stolen advertising accounts can fund fraudulent campaigns or be sold to other criminals. Island notes that attackers may add their own administrators and reduce the legitimate owner’s access, leaving recovery to drag on for weeks or months. 

Recruitment lures create a separate risk: employees who use workplace identities while applying for jobs could expose their employer’s email, files and business applications to unauthorized access.

Island recommends verifying unexpected beta programs, advertising tools and account connectors through official vendor websites. Users should inspect the real browser’s outermost address bar, not a window drawn inside the page. 

Security teams should correlate device-profiling requests, repeated password fields and operator-control events. Organizations should prioritize passkeys and hardware-backed authentication, with the shift toward phishing-resistant passkeys reducing dependence on reusable passwords and codes. 

After exposure, administrators should review every reachable client account for unfamiliar managers, changed recovery details and unauthorized campaigns or spending, rather than checking only the initial account.

IoCs and associated detection artifacts reproduced from Island’s source report follow. Legitimate services and spoofed destinations are explicitly distinguished from attacker infrastructure.

At Sterling Publishing & Media Service Agency, we prioritise transparency and accountability in all our operations. We wish to clarify that we are not responsible for any external content, hyperlinks, or costs associated with our services. Nevertheless, we remain committed to delivering outstanding services and greatly value your continued support. Thank you for your trust in us.

Leave a comment