A phishing campaign targeting advertising managers has expanded its repertoire to include a fake Meta Muse Ads product, just eight days after Meta launched its personal AI agent. The operation impersonates Gemini, Claude, ChatGPT, Perplexity, and Manus to steal credentials and multi-factor authentication codes.
Meta announced Muse on September 8, and by September 17 a convincing website—museads.ai—had appeared, advertising a product called Muse Ads that promised to help advertisers reach buyers and run sponsored placements.
“The operators already had the platform, so adapting it to a new brand can take minutes,” said Oleg Zaytsev, lead security researcher at Island, in an interview with The Register. “The striking part is how quickly they turned a timely announcement into a credible reason for someone to act. The same platform could then be repackaged around other familiar tasks, from connecting a business tool to claiming a refund or applying for a job.”
The security startup identified the Muse Ads webpage and discovered that only the page itself was new. “Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus,” Zaytsev and fellow Island researcher Ofek Ronen wrote in a blog post published Tuesday.
These products served as lures for browser-in-the-browser (BitB) attacks designed to trick agency staff, media buyers, and manager-account administrators into handing over advertising account credentials, stored payment methods, and client accounts.
“For victims, the potential cost is loss of access to an advertising account, unauthorized ad spend, and exposure of linked client accounts,” Zaytsev told The Register.
How the scam works
BitB is a phishing technique originally detailed by researcher mr.d0x in 2022. It involves building a fake login window directly inside a legitimate one. The fake window looks authentic, featuring an address bar, title, and URL, but it is merely an overlay designed to steal users’ credentials.
According to Zaytsev, the campaign has likely been very lucrative, with hundreds of victim submissions and ongoing activity.
“From one frontend alone, we observed submissions involving roughly 200 distinct email addresses over about a month,” he said. “The operators used the same platform across many similar sites, so we estimate the campaign-wide volume is substantially higher.”
Each phony ad product has its own page: ChatGPT promises a Monday Google Ads brief, Gemini offers manager account and linked-client support, Claude provides an advertising portal, Perplexity pitches campaign planning and spend audits, and Manus provides a private Meta integration.
Each fake product page also features a “connect” button. When the victim clicks “connect,” a browser-in-browser overlay opens, displaying a fake address bar showing accounts.google.com or an Okta tenant to gain the victim’s trust. The real browser remains on the phishing domain and captures credentials when the victim types them in.
A human operator running the campaign sees each submission and determines what the victim sees and is prompted to do. This includes asking for another password, requesting an SMS or Okta authenticator code to bypass MFA, showing a Google approval code or Okta push request, or displaying a QR code.
The platform supports Google, Meta, TikTok, and Okta workflows, and the browser overlay adapts to whatever the victim runs—Windows, macOS, iOS, or Android—mimicking Safari’s URL pill, Chrome’s custom tabs, and dark mode.
While the researchers have not identified the operators or found a name under which the kit is sold, the operators exposed older source code through misconfigured public GitHub repositories that connected this campaign to a larger operation.
In addition to the AI ad pages, the operation used fake refund claims and job recruitment sites as lures, with separate builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton.
All pages run on a Next.js and Socket.IO stack, with many using Vercel frontends and Railway or Render services behind them for state and commands.
“A new brand or polished page doesn’t necessarily mean a new attack. Operators can change the lure quickly, but the workflow still has to move someone onto a site they control, collect credentials, and steer them through authentication,” Zaytsev said.
“Security teams should maintain a continuous baseline of trusted domains, check the real browser address, and connect similar behavior across different sites,” he added. “Attackers can generate a convincing website quickly; building the domain history and reputation of a legitimate service is much harder. AI can help defenders keep pace with AI-generated websites, especially as they become more convincing and appear more quickly.”
Also Read
- NASA Announces Comprehensive Coverage Plans for Upcoming SpaceX Cargo Mission to International Space Station
- Microsoft Unveils New AI‑Powered Windows PCs with Nvidia RTX Spark Chips and Updated Windows 11
- Scientists Uncover Genetic and Epigenetic Secrets of Jonathan, the 194-Year-Old Tortoise
- AI Giants Race for .agent and .agi Domains in ICANN’s New TLD Wave


