StratosAlly – Cybersecurity for digital safety

Fake AI Ad Portals Use Counterfeit Login Windows to Steal Ad Accounts and MFA Codes

Picture of StratosAlly

StratosAlly

Fake AI website displaying a browser-in-browser phishing window designed to steal Google login credentials.

Fake AI ad portals are being used to hijack advertising accounts, Researchers at browser security firm Island have detailed a human-operated phishing platform that poses as advertising tools from Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse and Manus. Each brand gets its own pitch, from Google Ads briefs to manager-account (MCC) support, spend audits and a private Meta integration.
All of the mentioned services involve a Connect button that activates a Google, Meta, TikTok or Okta sign-in page while the bar displays some trusted sources like accounts.google.com. The page is actually a phishing webpage displaying a fake interface using a browser-in-the-browser (BitB) technology.
A human operator then takes over. The platform logs each password attempt, fingerprints the device and exchanges data with the operator over Socket.IO, while the attacker tries the credentials on the genuine account in real time. The operator has to decide on the next task: SMS verification, authenticator code, push notification from Okta, an approval message from Google or QR code. All verification methods may be either rejected or the victims of the phishing service may just wait until the operator ends their operation.
One example, museads.ai, appeared on September 16, 2026, a little over a week after Meta launched Muse. The AI ad pages are one of three tracks, alongside Google Ads refund lures and recruitment sites using the names of Tesla, Louis Vuitton, Nike and Adecco. All share a Next.js and Socket.IO stack. Source code exposed in misconfigured public GitHub repositories let researchers trace the activity back to March.
The people being attacked are agency personnel, media buyers, and account managers who have access to a number of clients. According to Island, the usual practice is for the attackers to add their own administrators while performing some downgrading of the legitimate owner; this sometimes takes weeks or months.
On the positive side, the defenders can distinguish a physical feature of the BitB windows because their content is “flat” and, thus, it cannot be moved out of the browser or resized as a regular OAuth pop-up. Island suggests banking on phishing-resistant forms of authentication while monitoring the modifications of the controls for advertising accounts and assessing AI-driven integrations before linking any accounts.

Let’s refine your stalking skills; go through our Instagram and LinkedIn.

more Related articles