Phishing Campaign Exploits Fake AI Chatbot Sites to Intercept Ad Manager Credentials

Cybercriminals are operating fraudulent versions of popular AI platforms like ChatGPT and Gemini to target advertising account managers, using browser-in-browser attacks to capture login credentials and multi-factor authentication codes. The malicious pages impersonate AI assistants designed for ad campaign management and feature realistic fake Google login windows embedded within the sites. Once compromised, these high-privilege advertising accounts can be used to launch fraudulent campaigns or sold to other criminals.
The phishing operation exploits the growing reliance on AI tools by targeting employees who manage advertising budgets across multiple client accounts. By impersonating legitimate platforms like ChatGPT and Gemini, attackers create a deceptive entry point for credential theft. The sophistication lies in the browser-in-browser technique, which renders a convincing fake login interface within the legitimate page, complete with a falsified address bar and multi-factor authentication interception capabilities controlled by human operators.
The broader criminal infrastructure supporting this campaign reveals a well-organized operation spanning several months. By leaving source code exposed through misconfigured GitHub repositories, researchers traced the activity back to March and identified connections to other phishing lures including fake job postings and refund scams. The attackers utilize a flexible platform supporting multiple authentication systems across Google, Meta, TikTok, and Okta, suggesting a service potentially offered to other bad actors.
This campaign could significantly impact advertising agencies and media buying firms, whose compromised accounts provide attackers access to substantial ad budgets and client data. The targeting of high-privilege accounts threatens not only individual organizations but their downstream clients who may be unaware of account compromise. Broader implications include potential erosion of trust in AI tools as legitimate business resources and increased pressure on companies to implement stronger authentication protocols and employee security awareness training.