MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via BleepingComputer

Phishing Campaign Exploits Fake AI Chatbot Sites to Intercept Ad Manager Credentials

Image via BleepingComputer
Image via BleepingComputer

Cybercriminals are operating fraudulent versions of popular AI platforms like ChatGPT and Gemini to target advertising account managers, using browser-in-browser attacks to capture login credentials and multi-factor authentication codes. The malicious pages impersonate AI assistants designed for ad campaign management and feature realistic fake Google login windows embedded within the sites. Once compromised, these high-privilege advertising accounts can be used to launch fraudulent campaigns or sold to other criminals.

Expanded Detail

The phishing operation exploits the growing reliance on AI tools by targeting employees who manage advertising budgets across multiple client accounts. By impersonating legitimate platforms like ChatGPT and Gemini, attackers create a deceptive entry point for credential theft. The sophistication lies in the browser-in-browser technique, which renders a convincing fake login interface within the legitimate page, complete with a falsified address bar and multi-factor authentication interception capabilities controlled by human operators.

The broader criminal infrastructure supporting this campaign reveals a well-organized operation spanning several months. By leaving source code exposed through misconfigured GitHub repositories, researchers traced the activity back to March and identified connections to other phishing lures including fake job postings and refund scams. The attackers utilize a flexible platform supporting multiple authentication systems across Google, Meta, TikTok, and Okta, suggesting a service potentially offered to other bad actors.

Context

This campaign could significantly impact advertising agencies and media buying firms, whose compromised accounts provide attackers access to substantial ad budgets and client data. The targeting of high-privilege accounts threatens not only individual organizations but their downstream clients who may be unaware of account compromise. Broader implications include potential erosion of trust in AI tools as legitimate business resources and increased pressure on companies to implement stronger authentication protocols and employee security awareness training.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Phishing Campaign Exploits FOMO With Counterfeit Brand Deals on Social Platforms · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes.” Browse more stories.