Fake AI Sites: How to Detect & Block BitB Ad Account Theft

•By CyberNewsAI Threat Research Team•VERIFIED INTEL
Browser-in-the-Browser phishing attacks hijacking corporate ad accounts through fake AI interfaces

SOC Briefing Summary :: Executive Key Takeaways

  • [01]A sophisticated cybercrime operation uses fake AI advertising platforms—spoofing ChatGPT, Gemini, Meta Muse, and Claude—to steal enterprise Google Ads Manager (MCC) and Okta credentials.
  • [02]The attack employs Browser-in-the-Browser (BitB) modal iframes with frosted toolbars that spoof accounts.google.com, backed by live human operators who relay MFA prompts via Socket.IO.
  • [03]Security teams must enforce origin-bound FIDO2 hardware tokens, audit MCC administrative roles, and deploy detection rules for BitB DOM artifacts and suspicious WebSocket relays.
SHARE INTEL:Reddit

Executive Summary

Threat researchers have uncovered an active, highly deceptive phishing operation targeting advertising agency personnel, media buyers, and corporate digital marketing administrators. Disguised as next-generation artificial intelligence advertising suites—impersonating brands including ChatGPT, Google Gemini, Anthropic Claude, Perplexity, and Meta’s newly launched Muse assistant—the fraudulent portals promise automated return-on-ad-spend (ROAS) audits and Google Ads Manager (MCC) synchronization.

Beneath the polished marketing interfaces sits an advanced implementation of the Browser-in-the-Browser (BitB) technique. When visitors attempt to connect their accounts, the page renders a synthetic browser window within an in-page modal iframe. Complete with an authentic-looking address bar pointing to accounts.google.com and an SSL padlock icon, the interface conceals the fact that the victim remains entirely within the phishing domain.

Behind the presentation layer, the campaign operates a live, human-in-the-loop state machine. When victims enter credentials, operators intercept the data over Socket.IO and Telegram command channels, selectively testing passwords and triggering live multi-factor authentication (MFA) challenges—including Google tap prompts, Okta Push verifications, and authenticator codes—in real time. The ultimate objective is the hijack of high-value advertising manager accounts to siphon linked corporate credit lines or resell aged accounts on cybercrime forums.

---

Technical Vulnerability Analysis & Attack Chain

Unlike traditional reverse-proxy phishing kits (such as Evilginx or Modlishka) that transparently forward HTTP traffic to legitimate identity providers, this platform locally recreates the provider interface and manages authentication states through custom API handlers.

Attack Chain Flow
// Attack Chain Flow

Root-Cause & Exploitation Mechanics

The campaign combines targeted corporate lures, high-fidelity UI emulation, and real-time adversary intervention:

  • Targeted Professional Lures: The attackers craft specialized landing pages using advertising terminology such as "MCC account sync," "ROAS audit," and "Monday brief integration." By capitalizing on recent tech announcements—such as registering museads.ai within eight days of Meta introducing Muse—the adversaries exploit professional curiosity and routine SaaS integration habits.
  • Adaptive BitB Presentation Layer: When the target clicks "Connect," JavaScript dynamically renders a fake browser window inside the current DOM. The toolkit detects the victim's operating system (Windows, macOS, iOS, or Android) and applies matching chrome styling. Source code recovered from misconfigured GitHub repositories reveals custom styling rules designed to mimic authentic browser chrome:
QUERY / DETECTION_RULE
CSS
/* Real iOS Safari and Chrome custom tabs use frosted toolbars */
.iab-chrome-translucent {
  backdrop-filter: saturate(180%) blur(20px);
}
  • Device Fingerprinting & State Registration: Prior to requesting credentials, the client registers the session via /api/create/user and queries public IP services (api.ipify.org, ipapi.co) before submitting device telemetry (screen resolution, user agent, WebGL fingerprint) to /api/send/ip.
  • Three-Attempt Password Harvesting: The backend state model maintains explicit fields for password_one, password_two, and password_three. If an operator suspects a mistyped password or seeks to capture secondary credentials, they issue a /password command to trigger a realistic "incorrect password" error while logging every submitted iteration.
  • Dynamic Human-in-the-Loop MFA Interception: Commands arrive over Socket.IO via operator-command and telegram-command events. While the victim is held on a simulated loading spinner, the human operator inputs the credentials into the genuine identity service and instructs the BitB modal to prompt the user accordingly:
    • /googlePrompt or /verifyTap: Displays specific Google two-digit tap challenge numbers.
    • /oktaApprove or /oktaAuthApp: Displays Okta Push verification or TOTP input fields.
    • /googleQrVerify: Renders a captured QR payload for identity authentication.
    • /wrong2fa: Prompts the user to re-enter a one-time code if the previous code expired.

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Initial AccessT1566.002Spearphishing LinkLures distributed via email and social media inviting marketers to test AI ad managers.
Defense EvasionT1566.004Phishing: Browser-in-the-BrowserIn-page CSS/JS modal iframes simulating legitimate browser windows and SSO URL bars.
Credential AccessT1556Modify Authentication ProcessLive operator intercepts passwords, TOTP codes, and device tap prompts via Socket.IO.
Credential AccessT1110.001Password Guessing / Retry CaptureBackend logs up to three distinct password attempts per victim (password_one through three).
Command & ControlT1071.001Web Protocols: WebSocket / Socket.IOReal-time bidirectional control channel coordinating victim prompts and attacker commands.
CollectionT1539Steal Web Session CookieHarvesting authenticated OAuth and SSO session cookies for Google, Meta, and Okta.

---

Threat Actor Profile & Campaign Attribution

Telemetry analyzed across the infrastructure reveals that this campaign represents an evolution of a modular cybercrime framework active since at least March 2026. The backend architecture—built on Next.js frontends hosted on Vercel and WebSocket backends on Railway (backend-production-6d75.up.railway.app) and Render—is routinely repurposed across three primary crime verticals:

  1. Ad Account Theft: Targeting Google Ads Manager (MCC), Meta Business Manager, and TikTok Ads.
  2. Refund Fraud: Spoofing payment confirmation and billing sync portals (refund-advertisers.com, payment-sync.com).
  3. Corporate Recruitment Scams: Hosting fake career and interview scheduling portals mimicking global brands (Tesla, Apple, Louis Vuitton, Adidas).

The Ad Account Resale Economy

Corporate advertising accounts represent high-yield monetization targets. An enterprise Google Ads Manager (MCC) account holds linked corporate credit lines, pre-approved spending limits, and downstream access to dozens of client accounts. Threat actors monetize stolen access through two primary avenues:

  • Direct Spend Burning: Launching unauthorized high-budget campaigns promoting cryptocurrency drainers, malware, or affiliate scams before the billing card is frozen.
  • Illicit Forum Resale: Aged advertising accounts with verified spend history sell on specialized Telegram marketplaces for $200 to $270 each (frequently commanding 2x to 4x premiums over newly created accounts).

---

Detection & SOC Mitigation Playbook

1. Concrete Remediation & Workarounds

Organizations operating digital marketing and media buying operations must enforce the following technical controls:

  1. Mandate Phishing-Resistant MFA (FIDO2 / Passkeys):

Migrate all Google Workspace and Okta administrative accounts to FIDO2 / WebAuthn hardware security keys. FIDO2 assertions are cryptographically bound to the genuine browser URL origin. Because the physical browser remains on the attacker's domain (e.g., museads.ai), hardware tokens refuse to negotiate credentials with the spoofed accounts.google.com modal.

  1. Verify Window Freedom:

Train marketing staff to conduct the "window freedom check": genuine OAuth login popups can be dragged outside the main browser viewport and resized independently. Browser-in-the-Browser modals are bound to the parent DOM and cannot cross the browser boundary.

  1. Audit Google Ads & Meta Administrative Hierarchies:

If an account manager reports entering credentials on an unverified site, immediately audit linked account relationships:

  • Check Google Ads MCC for unauthorized email addresses added under Tools & Settings > Access and Security.
  • Review pending partner access requests in Meta Business Manager.
  • Revoke active user sessions and refresh tokens across Google Workspace and Okta:
QUERY / DETECTION_RULE
POWERSHELL
# Revoke all active sessions for suspected victim via Microsoft Graph PowerShell
Revoke-MgUserSignAllSession -UserId "marketer@company.com"

2. Network & Perimeter Defenses

  • Block Known C2 Hosts: Restrict corporate network egress to suspicious WebSocket backends on Railway and Render associated with the campaign (e.g., *.up.railway.app and *.onrender.com instances serving untrusted origins).
  • Inspect WebSocket Traffic: Deploy secure web gateway (SWG) policies to alert on WebSocket connections originating from newly registered domains (< 30 days old) establishing connections to secondary hosting infrastructure.

3. Endpoint Detection & Hunting Query

Validated Sigma Rule (YAML)

QUERY / DETECTION_RULE
SIGMA / YAML
title: Potential Browser-in-the-Browser AI Phishing Domain Access
id: 4e9c71a3-2d58-4901-b8d1-5f72a912e840
status: experimental
description: Detects network navigation or DNS resolution targeting infrastructure associated with fake AI advertising platforms operating Browser-in-the-Browser phishing attacks.
author: CyberNewsAI Threat Research Team
date: 2026/10/06
references:
  - https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
  - https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
logsource:
  category: dns
detection:
  selection_domains:
    query|contains:
      - 'museads.ai'
      - 'advertising-chatgpt.com'
      - 'advertising-gemini.com'
      - 'ads-claude.com'
      - 'claude-ads-portal.com'
      - 'beta-perplexity.com'
      - 'mcc-account-sync.com'
      - 'sync-mcc-account.com'
      - 'mcc-verification.com'
      - 'chatgpt-monday-brief.com'
  selection_c2_patterns:
    query|contains:
      - 'backend-production-6d75.up.railway.app'
      - 'syncgoogleadsback.onrender.com'
      - 'claudeadsback-production.up.railway.app'
      - 'museadsback-production.up.railway.app'
  condition: selection_domains or selection_c2_patterns
falsepositives:
  - Legitimate domain research or sandbox testing environments
level: high
tags:
  - attack.initial_access
  - attack.t1566.002
  - attack.t1566.004

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Hunt for anomalous cloud sign-ins following navigation to suspicious advertising lures
// Correlates sign-in events with BitB token replay indicators
let TargetApps = dynamic(["Google Cloud Platform", "Google Workspace", "Okta", "Meta Business Suite"]);
let SuspiciousHostingASNs = dynamic(["RAILWAY", "RENDER", "DIGITALOCEAN", "HETZNER", "OVH"]);
SigninLogs
| where TimeGenerated >= ago(7d)
| where ResultType == 0 // Successful logon
| where AppDisplayName in~ (TargetApps)
| extend ClientDeviceType = tostring(DeviceDetail.operatingSystem)
| extend AuthMethod = tostring(AuthenticationRequirement)
| where NetworkLocationDetails has_any (SuspiciousHostingASNs)
    or AutonomousSystemNumber in (20473, 14061, 16276, 24940)
| project TimeGenerated, UserPrincipalName, IPAddress, Location, AppDisplayName, ClientAppUsed, UserAgent, AutonomousSystemNumber
| summarize ConnectionCount = count(), UniqueLocations = make_set(Location), Apps = make_set(AppDisplayName) by UserPrincipalName, IPAddress, UserAgent
| order by ConnectionCount desc

Splunk Hunting Query (SPL)

QUERY / DETECTION_RULE
SPLUNK / SPL
index=* sourcetype IN ("stream:http", "pan:traffic", "cisco:wsa:squid", "zscaler:web")
| eval lower_url=lower(url)
| where match(lower_url, "(museads\.ai|advertising-chatgpt\.com|advertising-gemini\.com|ads-claude\.com|claude-ads-portal\.com|beta-perplexity\.com|mcc-account-sync\.com|sync-mcc-account\.com)")
    OR match(lower_url, "\/api\/(create\/user|send\/ip)")
    OR match(lower_url, "backend-production-6d75\.up\.railway\.app")
| stats count min(_time) as first_seen max(_time) as last_seen values(url) as visited_urls values(user) as affected_users by src_ip, http_user_agent
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count

---

Indicator TypeValue / PatternOperational Context
Phishing Domainmuseads.aiPrimary Meta Muse AI advertising manager lure domain.
Phishing Domainadvertising-chatgpt.comFake ChatGPT advertising optimization lure.
Phishing Domainadvertising-gemini.comFake Google Gemini ad management lure.
Phishing Domainads-claude.comFake Anthropic Claude marketing portal.
Phishing Domainclaude-ads-portal.comSecondary Claude marketing lure.
Phishing Domainbeta-perplexity.comFake Perplexity campaign audit portal.
Phishing Domainmcc-account-sync.comGoogle Ads Manager (MCC) account synchronization spoof.
Phishing Domainsync-mcc-account.comGoogle Ads MCC credential harvesting portal.
C2 Backendbackend-production-6d75.up.railway.appShared Socket.IO command server observed across 70+ lure sites.
C2 Backendsyncgoogleadsback.onrender.comSecondary Render backend coordinating live Google account states.
API Endpoint/api/create/userClient registration endpoint initializing victim session state.
API Endpoint/api/send/ipDevice telemetry and WebGL fingerprint submission endpoint.
Socket Eventoperator-commandReal-time human attacker instructions issued to victim browser.
Socket Eventtelegram-commandTelegram-based C2 bridge dispatching MFA relay prompts.
Indicators of Compromise (IOCs)
7 Identified
Phishing Domainmuseads.ai
Phishing Domainadvertising-chatgpt.com
Phishing Domainadvertising-gemini.com
Phishing Domainads-claude.com
Phishing Domainmcc-account-sync.com
C2 Backendbackend-production-6d75.up.railway.app
C2 Backendsyncgoogleadsback.onrender.com
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE