Fake ChatGPT and Gemini sites target ad accounts and MFA codes
The campaign uses lookalike AI pages to capture logins and multi-factor prompts, putting advertising accounts and the data tied to them at risk.
Security researchers say a phishing campaign is abusing lookalike ChatGPT, Gemini, Claude, and Perplexity pages to steal advertising account logins and MFA codes, with the goal of hijacking high-value ad accounts or reselling access. The lure uses a browser-in-browser trick that opens a fake Google sign-in inside the page and can push victims through password, SMS, authenticator, push-approval, or QR-code prompts while a human operator controls the flow. Island’s researchers say the kit adapts to Windows, macOS, iOS, and Android, supports Google, Meta, TikTok, and Okta workflows, and sends commands over Socket.IO. They also tied the activity to a broader operation using fake recruiting and refund lures, with shared Next.js and Socket.IO infrastructure, Vercel frontends, Railway or Render backends, and older source code exposed in public GitHub repos. The Telegram control channel for the campaign had received hundreds of victim submissions, though that does not prove the same number of accounts were fully compromised.
Why it matters
For advertisers and anyone managing brand accounts, the risk is not just a stolen password. The fake sign-in flow is designed to carry victims through MFA prompts as well, which can give attackers a cleaner path to account access and let them resell or reuse the access once they get in.
Keep or strike?
Does this story matter, or is it hype? Mark it before you see what everyone else did.
Sources
- BleepingComputer