Security2 publishersIndependently confirmed2 min readPublished
Fake ChatGPT and Gemini ad tools phish agency logins that unlock several clients' budgets
Island traced fake ChatGPT, Gemini, Claude and Perplexity ad tools to a phishing operation whose Telegram channel took hundreds of victim submissions. Its targets are agency buyers and admins, whose one login can spend several advertisers' balances.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The phishers built their pitch around Meta's recent Muse AI agent launch, offering fake tools that promise ad briefs, buyer reach and campaign audits.
- A 'connect' button opens a fake Google sign-in window drawn inside the page, its address bar showing accounts.google.com.
- Once a victim is in, a live operator picks the prompts: the password up to three times, then SMS or authenticator codes, Okta pushes, Google approvals or QR codes.
- Older source code left in misconfigured public GitHub repositories let Island tie the ad pages to refund and recruitment lures going back to March.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Advertisers who never saw the fake page take the loss, because one agency login reaches their balances, which can be spent on fraudulent campaigns or sold on.
- constraint SMS codes, authenticator codes and push approvals fail against this flow, since each one goes to an operator who can reject it and ask again.
- precedent The operation has already run refund, recruitment and AI-tool lures on one stack, so the next heavily covered product launch is a likely next pitch.
The campaign needs no software flaw. It is phishing aimed at the people who hold ad accounts. It is built on browser-in-the-browser, a technique a security researcher published in March 2022 that has been used heavily since, including against Steam accounts [1][20]. Island describes a kit tuned for ad-platform logins. It supports Google, Meta, TikTok and Okta sign-in flows [15] and redraws itself for Windows, macOS, iOS or Android, down to browser styling and dark mode [8].
Island's researchers separate it from proxy-based phishing. "Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs," they wrote [16]. Operator commands travel as Socket.IO events [15]. On the wire, the session appears to be an AI product talking to an unrelated application backend [17].
The fake window has one physical limit. A genuine OAuth pop-up can be dragged outside the browser window and resized. The fake one is an iframe and can do neither [7][22].
The ad pages are one lure among several. I'd treat the operation as a standing service that swaps lures on fixed infrastructure [12][14]. Every page tied to it shares a Next.js and Socket.IO stack and common API endpoints, and many run on Vercel frontends with Railway or Render backends [13]. Island counted dozens of URLs across the ad, refund and recruitment campaigns and published the list with its report [18].
Scale is the weak part of the public record. Island cautions that the submission count in the operators' Telegram channel does not necessarily match the number of accounts actually compromised [21]. BleepingComputer's account of the research does not name a threat actor or give a figure for ad spend lost [19].
What to watch
- Whether Meta, Google or TikTok report agency ad-account takeovers or fraudulent spend linked to this kit.
- Whether the operation moves off Vercel, Railway and Render, or rebuilds its URLs, now that Island has published the list.
- Whether Island or another firm attributes the operation or publishes a confirmed count of compromised accounts.