cybersecuritynews.com
Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes
Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes.
Instead of delivering a conventional malware download, the campaign uses convincing websites and live human operators to guide victims through fraudulent sign-in screens.
Invitation emails lead advertisers to pages promising campaign planning, spending audits and account connections. The approach echoes earlier attacks involving fake AI advertising apps , which used familiar technology brands to make credential requests appear legitimate.
Island.io researchers Oleg Zaytsev and Ofek Ronen identified the operation and observed hundreds of victim submissions, with activity continuing when their findings were published on October 6, 2026.
Island.io said in a report shared with Cyber Security News (CSN) that attackers could reject passwords, select authentication challenges and redirect victims after completing the flow.
Victim data and operator commands (Source – Island.io)
The campaign targets agency employees, media buyers and advertising account administrators. A single compromised manager account can expose several clients, their billing profiles and approved advertising budgets, turning an apparently routine integration request into a potentially expensive business incident.
Hackers Use Fake ChatGPT, Claude and Gemini Ads
Each fake product offers a tailored reason to connect an account. ChatGPT impersonations promise a weekly Google Ads briefing, Gemini pages advertise manager-account support, and Claude receives its own advertising portal.
Perplexity and Manus branding also appear across the operation. The newest lure, Muse Ads, appeared by September 16, eight days after Meta announced Muse.
Researchers found that its sign-in forms and fake browser window reused the wider platform’s existing code, showing how quickly operators could attach a new product story to established infrastructure.
Spoofed Tesla recruitment page (Source – Island.io)
Clicking Connect does not open a genuine Google authentication window. Instead, the website draws a second browser inside the real one, using the browser within browser technique to display a convincing address bar and lock icon while the actual page remains on attacker-controlled infrastructure.
The imitation adjusts to Windows, macOS, iOS and Android. Newer versions reproduce details such as dark mode, mobile browser controls and translucent toolbars. These touches make the false window look familiar without changing the real browser’s address or origin.
Behind that interface, the platform records device characteristics, location and submitted credentials. It preserves three separate password attempts, allowing an operator to claim that an entry failed, request another and retain every value the victim provides.
Human operators then choose the next authentication step while attempting the real login. Supported prompts include text-message codes, authenticator codes, Google approvals, QR verification, number matching and Okta push requests. A waiting screen keeps victims engaged while the attacker decides what to request next.
Shared Infrastructure and Account Protection
The same Next.js and Socket.IO platform supports AI advertising pages, refund claims and fake recruitment sites. Researchers linked one backend to 73 archived scans covering 25 page domains between May 27 and June 20, connecting apparently unrelated lures through shared infrastructure.
Older source code exposed through public GitHub repositories revealed matching routes, the three-password retry model and Telegram-based controls.
AI-branded phishing lures (Source – Island.io)
The visible platform rebuilds login interfaces locally rather than transparently forwarding an identity provider’s website, making its traffic resemble ordinary application activity.
Stolen advertising accounts can fund fraudulent campaigns or be sold to other criminals. Island notes that attackers may add their own administrators and reduce the legitimate owner’s access, leaving recovery to drag on for weeks or months.
Recruitment lures create a separate risk: employees who use workplace identities while applying for jobs could expose their employer’s email, files and business applications to unauthorized access.
Island recommends verifying unexpected beta programs, advertising tools and account connectors through official vendor websites. Users should inspect the real browser’s outermost address bar, not a window drawn inside the page.
Security teams should correlate device-profiling requests, repeated password fields and operator-control events. Organizations should prioritize passkeys and hardware-backed authentication, with the shift toward phishing-resistant passkeys reducing dependence on reusable passwords and codes.
After exposure, administrators should review every reachable client account for unfamiliar managers, changed recovery details and unauthorized campaigns or spending, rather than checking only the initial account.
IoCs and associated detection artifacts reproduced from Island’s source report follow. Legitimate services and spoofed destinations are explicitly distinguished from attacker infrastructure.
Indicators of compromise (IoCs):-
Type Indicator Description Domain account-sync-data.com Advertising phishing domain Domain ads-claude-beta.com Advertising phishing domain Domain ads-claude.com Advertising phishing domain Domain ads-team-openai.com Advertising phishing domain Domain adsmistral.com Advertising phishing domain Domain advertising-chatgpt.com Advertising phishing domain Domain advertising-gemini.com Advertising phishing domain Domain ai-ads-platform.com Advertising phishing domain Domain ai-brand-safety.com Advertising phishing domain Domain anthropic-ads-beta.com Advertising phishing domain Domain anthropic-ads-marketing.com Advertising phishing domain Domain anthropic-ads.com Advertising phishing domain Domain anthropic-beta-ads.com Advertising phishing domain Domain anthropic-crm-1.com Advertising phishing domain Domain anthropic-sponsored.com Advertising phishing domain Domain beta-anthropic.com Advertising phishing domain Domain beta-chatgpt.com Advertising phishing domain Domain beta-gemini-ads.com Advertising phishing domain Domain beta-manus.com Advertising phishing domain Domain beta-perplexity.com Advertising phishing domain Domain business-gemini.com Advertising phishing domain Domain chatgpt-advertise.com Advertising phishing domain Domain chatgpt-advertisement.com Advertising phishing domain Domain chatgpt-beta.com Advertising phishing domain Domain chatgpt-brief.com Advertising phishing domain Domain chatgpt-briefing.com Advertising phishing domain Domain chatgpt-monday-brief.com Advertising phishing domain Domain claude-ads-beta.com Advertising phishing domain Domain claude-ads-invitations.com Advertising phishing domain Domain claude-ads-portal.com Advertising phishing domain Domain claude-ads.ai Advertising phishing domain Domain claude-advertisement.com Advertising phishing domain Domain claude-advertisers.ai Advertising phishing domain Domain claude-advertisers.com Advertising phishing domain Domain claude-beta-invite.com Advertising phishing domain Domain claude-beta.com Advertising phishing domain Domain cursor-ads.com Advertising phishing domain Domain escrow-ads.com Advertising phishing domain Domain gemimi-ads.com Advertising phishing domain Domain gemini-ads-ai.com Advertising phishing domain Domain gemini-ads-invite.com Advertising phishing domain Domain gemini-ads-team.com Advertising phishing domain Domain gemini-ads.ai Advertising phishing domain Domain gemini-advertisers.com Advertising phishing domain Domain gemini-beta-invitations.com Advertising phishing domain Domain gemini-beta-invites.com Advertising phishing domain Domain gemini-business.com Advertising phishing domain Domain gemini-google-ads.com Advertising phishing domain Domain gemini-invitation.com Advertising phishing domain Domain gemini-invitations.com Advertising phishing domain Domain gennini-ads.com Advertising phishing domain Domain google-ads-sync.com Advertising phishing domain Domain invitation-anthropic.com Advertising phishing domain Domain leaks-entry.com Advertising phishing domain Domain leaksentry-security.com Advertising phishing domain Domain link-mcc.com Advertising phishing domain Domain manus-meta.im Advertising phishing domain Domain manusbymeta.com Advertising phishing domain Domain manusmeta.im Advertising phishing domain Domain mcc-account-sync.com Advertising phishing domain Domain mcc-invitation.com Advertising phishing domain Domain mcc-safety.com Advertising phishing domain Domain mcc-security.com Advertising phishing domain Domain mcc-verification.com Advertising phishing domain Domain metamanus.im Advertising phishing domain Domain monday-brief-claude.com Advertising phishing domain Domain museads.ai Advertising phishing domain Domain openai-ads.ai Advertising phishing domain Domain openai-advertisers.com Advertising phishing domain Domain openaiadsteam.com Advertising phishing domain Domain perplexity-advertising.com Advertising phishing domain Domain perplexity-beta-ads.com Advertising phishing domain Domain perplexity-beta.com Advertising phishing domain Domain safety-mcc.com Advertising phishing domain Domain security-ads.com Advertising phishing domain Domain security-mcc.com Advertising phishing domain Domain semrush-ai.com Advertising phishing domain Domain semrushads-ai.com Advertising phishing domain Domain sponsored-gemini.com Advertising phishing domain Domain sync-account-invite.com Advertising phishing domain Domain sync-account.com Advertising phishing domain Domain sync-ads-account.com Advertising phishing domain Domain sync-ads.com Advertising phishing domain Domain sync-business.com Advertising phishing domain Domain sync-mcc-account.com Advertising phishing domain Domain sync-mcc-data.com Advertising phishing domain Domain sync-mcc-team.com Advertising phishing domain Domain sync-tiktok.com Advertising phishing domain Domain verification-security.com Advertising phishing domain Backend host adsclaudeback-production.up.railway.app Advertising campaign backend Backend host anthropicadsback.onrender.com Advertising campaign backend Backend host backend-j02u.onrender.com Advertising campaign backend Backend host backend-production-6d75.up.railway.app Shared advertising, refund and recruitment backend Backend host backend-tg0j.onrender.com Advertising campaign backend Backend host chatgptadsback-production.up.railway.app Advertising campaign backend Backend host chatgptadsback.onrender.com Advertising campaign backend Backend host claudeadsback-production-67c1.up.railway.app Advertising campaign backend Backend host claudeadsback-production.up.railway.app Advertising campaign backend Backend host geminiback-5j1n.onrender.com Advertising campaign backend Backend host geminiback-production.up.railway.app Advertising campaign backend Backend host just-cooperation-production-f159.up.railway.app Advertising campaign backend Backend host manus2back-production.up.railway.app Advertising campaign backend Backend host manusback-bahk.onrender.com Advertising campaign backend Backend host manusback-production.up.railway.app Advertising campaign backend Backend host manusback.onrender.com Advertising campaign backend Backend host mbackend-mdye.onrender.com Advertising campaign backend Backend host museadsback-production.up.railway.app Advertising campaign backend Backend host semrushback.onrender.com Advertising campaign backend Backend host syncgadsback.onrender.com Advertising campaign backend Backend host syncgoogleadsback-production-6100.up.railway.app Advertising campaign backend Backend host syncgoogleadsback-production-cde6.up.railway.app Advertising campaign backend Backend host syncgoogleadsback-production.up.railway.app Advertising campaign backend Backend host syncgoogleadsback.onrender.com Advertising campaign backend Backend host tbackend-production-39ca.up.railway.app Advertising campaign backend Domain confirm-payments.com Refund phishing domain Domain payment-confirm.com Refund phishing domain Domain payment-confirmation.com Refund phishing domain Domain payment-confirmations.com Refund phishing domain Domain payment-sync.com Refund phishing domain Domain payments-sync.com Refund phishing domain Domain refund-advertisers.com Refund phishing domain Domain sync-billing.com Refund phishing domain Domain sync-payment.com Refund phishing domain Domain sync-payments.com Refund phishing domain Domain adeccohr-calendly.com Recruitment phishing domain Domain adeccohr-jobs.com Recruitment phishing domain Domain apple-career.com Recruitment phishing domain Domain nikehr-jobs.com Recruitment phishing domain Domain talent-louisvuitton.com Recruitment phishing domain Backend host nikear.onrender.com Recruitment campaign backend Backend host zero39172-391920.onrender.com Recruitment campaign backend Domain careers-interview.com Recruitment phishing domain Domain ferrar.careers-interview.com Recruitment phishing domain Domain ferrari-invite.com Recruitment phishing domain Domain redbullapply.careers-appointment.com Recruitment phishing domain Domain tesla-careerapplication.com Recruitment phishing domain Backend host mango-back.onrender.com Recruitment campaign backend Legitimate domain accounts.google.com Spoofed address-bar destination, not attacker infrastructure Legitimate service api.ipify.org IP lookup service used in profiling; not independently malicious Legitimate service ipapi.co IP information service used in profiling; not independently malicious API path /api/create/user Creates a victim record API path /api/send/ip Receives device and IP profiling information State field google_uid Client-pattern detection artifact State field password_one Stores the first password submission State field password_two Stores the second password submission State field password_three Stores the third password submission Control event add-user Platform control-vocabulary artifact Control event update-user Platform control-vocabulary artifact Control event operator-command Delivers operator instructions Control event telegram-command Delivers Telegram-linked instructions Operator command /password Requests another password Operator command /2fa Requests an SMS code Operator command /authApp Requests an authenticator code Operator command /googlePrompt Displays a Google approval prompt Operator command /googleQrVerify Displays a supplied QR payload Operator command /verifyTap Displays a supplied tap number Operator command /oktaApprove Displays an Okta push request Operator command /oktaAuthApp Requests an Okta authenticator code Operator command /wrong2fa Rejects the current authentication code Operator command /done Completes the phishing flow Operator command /ban Suppresses the page for the visitor GitHub repository recruiterid/teslanewnewne Exposed recruitment frontend source GitHub repository recruiterid/newnewtesla Exposed recruitment backend source GitHub account reudisace Published related recruitment builds
Note: IP addresses and domains are intentionally defanged (e.g., [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM .
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
The post Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes appeared first on Cyber Security News .