Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are impersonating ChatGPT, Claude and Gemini with fake advertising products that steal passwords and multifactor authentication codes.

Instead of delivering a conventional malware download, the campaign uses convincing websites and live human operators to guide victims through fraudulent sign-in screens.

Invitation emails lead advertisers to pages promising campaign planning, spending audits and account connections. The approach echoes earlier attacks involving fake AI advertising apps, which used familiar technology brands to make credential requests appear legitimate.

Island.io researchers Oleg Zaytsev and Ofek Ronen identified the operation and observed hundreds of victim submissions, with activity continuing when their findings were published on October 6, 2026.

Island.io said in a report shared with Cyber Security News (CSN) that attackers could reject passwords, select authentication challenges and redirect victims after completing the flow.

Victim data and operator commands (Source - Island.io)
Victim data and operator commands (Source – Island.io)

The campaign targets agency employees, media buyers and advertising account administrators. A single compromised manager account can expose several clients, their billing profiles and approved advertising budgets, turning an apparently routine integration request into a potentially expensive business incident.

Hackers Use Fake ChatGPT, Claude and Gemini Ads

Each fake product offers a tailored reason to connect an account. ChatGPT impersonations promise a weekly Google Ads briefing, Gemini pages advertise manager-account support, and Claude receives its own advertising portal.

Perplexity and Manus branding also appear across the operation. The newest lure, Muse Ads, appeared by September 16, eight days after Meta announced Muse.

Researchers found that its sign-in forms and fake browser window reused the wider platform’s existing code, showing how quickly operators could attach a new product story to established infrastructure.

Spoofed Tesla recruitment page (Source - Island.io)
Spoofed Tesla recruitment page (Source – Island.io)

Clicking Connect does not open a genuine Google authentication window. Instead, the website draws a second browser inside the real one, using the browser within browser technique to display a convincing address bar and lock icon while the actual page remains on attacker-controlled infrastructure.

The imitation adjusts to Windows, macOS, iOS and Android. Newer versions reproduce details such as dark mode, mobile browser controls and translucent toolbars. These touches make the false window look familiar without changing the real browser’s address or origin.

Behind that interface, the platform records device characteristics, location and submitted credentials. It preserves three separate password attempts, allowing an operator to claim that an entry failed, request another and retain every value the victim provides.

Human operators then choose the next authentication step while attempting the real login. Supported prompts include text-message codes, authenticator codes, Google approvals, QR verification, number matching and Okta push requests. A waiting screen keeps victims engaged while the attacker decides what to request next.

Shared Infrastructure and Account Protection

The same Next.js and Socket.IO platform supports AI advertising pages, refund claims and fake recruitment sites. Researchers linked one backend to 73 archived scans covering 25 page domains between May 27 and June 20, connecting apparently unrelated lures through shared infrastructure.

Older source code exposed through public GitHub repositories revealed matching routes, the three-password retry model and Telegram-based controls.

AI-branded phishing lures (Source - Island.io)
AI-branded phishing lures (Source – Island.io)

The visible platform rebuilds login interfaces locally rather than transparently forwarding an identity provider’s website, making its traffic resemble ordinary application activity.

Stolen advertising accounts can fund fraudulent campaigns or be sold to other criminals. Island notes that attackers may add their own administrators and reduce the legitimate owner’s access, leaving recovery to drag on for weeks or months.

Recruitment lures create a separate risk: employees who use workplace identities while applying for jobs could expose their employer’s email, files and business applications to unauthorized access.

Island recommends verifying unexpected beta programs, advertising tools and account connectors through official vendor websites. Users should inspect the real browser’s outermost address bar, not a window drawn inside the page.

Security teams should correlate device-profiling requests, repeated password fields and operator-control events. Organizations should prioritize passkeys and hardware-backed authentication, with the shift toward phishing-resistant passkeys reducing dependence on reusable passwords and codes.

After exposure, administrators should review every reachable client account for unfamiliar managers, changed recovery details and unauthorized campaigns or spending, rather than checking only the initial account.

IoCs and associated detection artifacts reproduced from Island’s source report follow. Legitimate services and spoofed destinations are explicitly distinguished from attacker infrastructure.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain account-sync-data.com Advertising phishing domain
Domain ads-claude-beta.com Advertising phishing domain
Domain ads-claude.com Advertising phishing domain
Domain ads-team-openai.com Advertising phishing domain
Domain adsmistral.com Advertising phishing domain
Domain advertising-chatgpt.com Advertising phishing domain
Domain advertising-gemini.com Advertising phishing domain
Domain ai-ads-platform.com Advertising phishing domain
Domain ai-brand-safety.com Advertising phishing domain
Domain anthropic-ads-beta.com Advertising phishing domain
Domain anthropic-ads-marketing.com Advertising phishing domain
Domain anthropic-ads.com Advertising phishing domain
Domain anthropic-beta-ads.com Advertising phishing domain
Domain anthropic-crm-1.com Advertising phishing domain
Domain anthropic-sponsored.com Advertising phishing domain
Domain beta-anthropic.com Advertising phishing domain
Domain beta-chatgpt.com Advertising phishing domain
Domain beta-gemini-ads.com Advertising phishing domain
Domain beta-manus.com Advertising phishing domain
Domain beta-perplexity.com Advertising phishing domain
Domain business-gemini.com Advertising phishing domain
Domain chatgpt-advertise.com Advertising phishing domain
Domain chatgpt-advertisement.com Advertising phishing domain
Domain chatgpt-beta.com Advertising phishing domain
Domain chatgpt-brief.com Advertising phishing domain
Domain chatgpt-briefing.com Advertising phishing domain
Domain chatgpt-monday-brief.com Advertising phishing domain
Domain claude-ads-beta.com Advertising phishing domain
Domain claude-ads-invitations.com Advertising phishing domain
Domain claude-ads-portal.com Advertising phishing domain
Domain claude-ads.ai Advertising phishing domain
Domain claude-advertisement.com Advertising phishing domain
Domain claude-advertisers.ai Advertising phishing domain
Domain claude-advertisers.com Advertising phishing domain
Domain claude-beta-invite.com Advertising phishing domain
Domain claude-beta.com Advertising phishing domain
Domain cursor-ads.com Advertising phishing domain
Domain escrow-ads.com Advertising phishing domain
Domain gemimi-ads.com Advertising phishing domain
Domain gemini-ads-ai.com Advertising phishing domain
Domain gemini-ads-invite.com Advertising phishing domain
Domain gemini-ads-team.com Advertising phishing domain
Domain gemini-ads.ai Advertising phishing domain
Domain gemini-advertisers.com Advertising phishing domain
Domain gemini-beta-invitations.com Advertising phishing domain
Domain gemini-beta-invites.com Advertising phishing domain
Domain gemini-business.com Advertising phishing domain
Domain gemini-google-ads.com Advertising phishing domain
Domain gemini-invitation.com Advertising phishing domain
Domain gemini-invitations.com Advertising phishing domain
Domain gennini-ads.com Advertising phishing domain
Domain google-ads-sync.com Advertising phishing domain
Domain invitation-anthropic.com Advertising phishing domain
Domain leaks-entry.com Advertising phishing domain
Domain leaksentry-security.com Advertising phishing domain
Domain link-mcc.com Advertising phishing domain
Domain manus-meta.im Advertising phishing domain
Domain manusbymeta.com Advertising phishing domain
Domain manusmeta.im Advertising phishing domain
Domain mcc-account-sync.com Advertising phishing domain
Domain mcc-invitation.com Advertising phishing domain
Domain mcc-safety.com Advertising phishing domain
Domain mcc-security.com Advertising phishing domain
Domain mcc-verification.com Advertising phishing domain
Domain metamanus.im Advertising phishing domain
Domain monday-brief-claude.com Advertising phishing domain
Domain museads.ai Advertising phishing domain
Domain openai-ads.ai Advertising phishing domain
Domain openai-advertisers.com Advertising phishing domain
Domain openaiadsteam.com Advertising phishing domain
Domain perplexity-advertising.com Advertising phishing domain
Domain perplexity-beta-ads.com Advertising phishing domain
Domain perplexity-beta.com Advertising phishing domain
Domain safety-mcc.com Advertising phishing domain
Domain security-ads.com Advertising phishing domain
Domain security-mcc.com Advertising phishing domain
Domain semrush-ai.com Advertising phishing domain
Domain semrushads-ai.com Advertising phishing domain
Domain sponsored-gemini.com Advertising phishing domain
Domain sync-account-invite.com Advertising phishing domain
Domain sync-account.com Advertising phishing domain
Domain sync-ads-account.com Advertising phishing domain
Domain sync-ads.com Advertising phishing domain
Domain sync-business.com Advertising phishing domain
Domain sync-mcc-account.com Advertising phishing domain
Domain sync-mcc-data.com Advertising phishing domain
Domain sync-mcc-team.com Advertising phishing domain
Domain sync-tiktok.com Advertising phishing domain
Domain verification-security.com Advertising phishing domain
Backend host adsclaudeback-production.up.railway.app Advertising campaign backend
Backend host anthropicadsback.onrender.com Advertising campaign backend
Backend host backend-j02u.onrender.com Advertising campaign backend
Backend host backend-production-6d75.up.railway.app Shared advertising, refund and recruitment backend
Backend host backend-tg0j.onrender.com Advertising campaign backend
Backend host chatgptadsback-production.up.railway.app Advertising campaign backend
Backend host chatgptadsback.onrender.com Advertising campaign backend
Backend host claudeadsback-production-67c1.up.railway.app Advertising campaign backend
Backend host claudeadsback-production.up.railway.app Advertising campaign backend
Backend host geminiback-5j1n.onrender.com Advertising campaign backend
Backend host geminiback-production.up.railway.app Advertising campaign backend
Backend host just-cooperation-production-f159.up.railway.app Advertising campaign backend
Backend host manus2back-production.up.railway.app Advertising campaign backend
Backend host manusback-bahk.onrender.com Advertising campaign backend
Backend host manusback-production.up.railway.app Advertising campaign backend
Backend host manusback.onrender.com Advertising campaign backend
Backend host mbackend-mdye.onrender.com Advertising campaign backend
Backend host museadsback-production.up.railway.app Advertising campaign backend
Backend host semrushback.onrender.com Advertising campaign backend
Backend host syncgadsback.onrender.com Advertising campaign backend
Backend host syncgoogleadsback-production-6100.up.railway.app Advertising campaign backend
Backend host syncgoogleadsback-production-cde6.up.railway.app Advertising campaign backend
Backend host syncgoogleadsback-production.up.railway.app Advertising campaign backend
Backend host syncgoogleadsback.onrender.com Advertising campaign backend
Backend host tbackend-production-39ca.up.railway.app Advertising campaign backend
Domain confirm-payments.com Refund phishing domain
Domain payment-confirm.com Refund phishing domain
Domain payment-confirmation.com Refund phishing domain
Domain payment-confirmations.com Refund phishing domain
Domain payment-sync.com Refund phishing domain
Domain payments-sync.com Refund phishing domain
Domain refund-advertisers.com Refund phishing domain
Domain sync-billing.com Refund phishing domain
Domain sync-payment.com Refund phishing domain
Domain sync-payments.com Refund phishing domain
Domain adeccohr-calendly.com Recruitment phishing domain
Domain adeccohr-jobs.com Recruitment phishing domain
Domain apple-career.com Recruitment phishing domain
Domain nikehr-jobs.com Recruitment phishing domain
Domain talent-louisvuitton.com Recruitment phishing domain
Backend host nikear.onrender.com Recruitment campaign backend
Backend host zero39172-391920.onrender.com Recruitment campaign backend
Domain careers-interview.com Recruitment phishing domain
Domain ferrar.careers-interview.com Recruitment phishing domain
Domain ferrari-invite.com Recruitment phishing domain
Domain redbullapply.careers-appointment.com Recruitment phishing domain
Domain tesla-careerapplication.com Recruitment phishing domain
Backend host mango-back.onrender.com Recruitment campaign backend
Legitimate domain accounts.google.com Spoofed address-bar destination, not attacker infrastructure
Legitimate service api.ipify.org IP lookup service used in profiling; not independently malicious
Legitimate service ipapi.co IP information service used in profiling; not independently malicious
API path /api/create/user Creates a victim record
API path /api/send/ip Receives device and IP profiling information
State field google_uid Client-pattern detection artifact
State field password_one Stores the first password submission
State field password_two Stores the second password submission
State field password_three Stores the third password submission
Control event add-user Platform control-vocabulary artifact
Control event update-user Platform control-vocabulary artifact
Control event operator-command Delivers operator instructions
Control event telegram-command Delivers Telegram-linked instructions
Operator command /password Requests another password
Operator command /2fa Requests an SMS code
Operator command /authApp Requests an authenticator code
Operator command /googlePrompt Displays a Google approval prompt
Operator command /googleQrVerify Displays a supplied QR payload
Operator command /verifyTap Displays a supplied tap number
Operator command /oktaApprove Displays an Okta push request
Operator command /oktaAuthApp Requests an Okta authenticator code
Operator command /wrong2fa Rejects the current authentication code
Operator command /done Completes the phishing flow
Operator command /ban Suppresses the page for the visitor
GitHub repository recruiterid/teslanewnewne Exposed recruitment frontend source
GitHub repository recruiterid/newnewtesla Exposed recruitment backend source
GitHub account reudisace Published related recruitment builds

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Hackers Use Fake ChatGPT, Claude and Gemini Ads to Steal Passwords and MFA Codes appeared first on Cyber Security News.