Fake AI Sites: How to Detect & Block BitB Ad Account Theft

SOC Briefing Summary :: Executive Key Takeaways
- [01]A sophisticated cybercrime operation uses fake AI advertising platforms—spoofing ChatGPT, Gemini, Meta Muse, and Claude—to steal enterprise Google Ads Manager (MCC) and Okta credentials.
- [02]The attack employs Browser-in-the-Browser (BitB) modal iframes with frosted toolbars that spoof accounts.google.com, backed by live human operators who relay MFA prompts via Socket.IO.
- [03]Security teams must enforce origin-bound FIDO2 hardware tokens, audit MCC administrative roles, and deploy detection rules for BitB DOM artifacts and suspicious WebSocket relays.
Executive Summary
Threat researchers have uncovered an active, highly deceptive phishing operation targeting advertising agency personnel, media buyers, and corporate digital marketing administrators. Disguised as next-generation artificial intelligence advertising suites—impersonating brands including ChatGPT, Google Gemini, Anthropic Claude, Perplexity, and Meta’s newly launched Muse assistant—the fraudulent portals promise automated return-on-ad-spend (ROAS) audits and Google Ads Manager (MCC) synchronization.
Beneath the polished marketing interfaces sits an advanced implementation of the Browser-in-the-Browser (BitB) technique. When visitors attempt to connect their accounts, the page renders a synthetic browser window within an in-page modal iframe. Complete with an authentic-looking address bar pointing to accounts.google.com and an SSL padlock icon, the interface conceals the fact that the victim remains entirely within the phishing domain.
Behind the presentation layer, the campaign operates a live, human-in-the-loop state machine. When victims enter credentials, operators intercept the data over Socket.IO and Telegram command channels, selectively testing passwords and triggering live multi-factor authentication (MFA) challenges—including Google tap prompts, Okta Push verifications, and authenticator codes—in real time. The ultimate objective is the hijack of high-value advertising manager accounts to siphon linked corporate credit lines or resell aged accounts on cybercrime forums.
---
Technical Vulnerability Analysis & Attack Chain
Unlike traditional reverse-proxy phishing kits (such as Evilginx or Modlishka) that transparently forward HTTP traffic to legitimate identity providers, this platform locally recreates the provider interface and manages authentication states through custom API handlers.

Root-Cause & Exploitation Mechanics
The campaign combines targeted corporate lures, high-fidelity UI emulation, and real-time adversary intervention:
- Targeted Professional Lures: The attackers craft specialized landing pages using advertising terminology such as "MCC account sync," "ROAS audit," and "Monday brief integration." By capitalizing on recent tech announcements—such as registering
museads.aiwithin eight days of Meta introducing Muse—the adversaries exploit professional curiosity and routine SaaS integration habits. - Adaptive BitB Presentation Layer: When the target clicks "Connect," JavaScript dynamically renders a fake browser window inside the current DOM. The toolkit detects the victim's operating system (Windows, macOS, iOS, or Android) and applies matching chrome styling. Source code recovered from misconfigured GitHub repositories reveals custom styling rules designed to mimic authentic browser chrome:
/* Real iOS Safari and Chrome custom tabs use frosted toolbars */
.iab-chrome-translucent {
backdrop-filter: saturate(180%) blur(20px);
}- Device Fingerprinting & State Registration: Prior to requesting credentials, the client registers the session via
/api/create/userand queries public IP services (api.ipify.org,ipapi.co) before submitting device telemetry (screen resolution, user agent, WebGL fingerprint) to/api/send/ip. - Three-Attempt Password Harvesting: The backend state model maintains explicit fields for
password_one,password_two, andpassword_three. If an operator suspects a mistyped password or seeks to capture secondary credentials, they issue a/passwordcommand to trigger a realistic "incorrect password" error while logging every submitted iteration. - Dynamic Human-in-the-Loop MFA Interception: Commands arrive over Socket.IO via
operator-commandandtelegram-commandevents. While the victim is held on a simulated loading spinner, the human operator inputs the credentials into the genuine identity service and instructs the BitB modal to prompt the user accordingly:/googlePromptor/verifyTap: Displays specific Google two-digit tap challenge numbers./oktaApproveor/oktaAuthApp: Displays Okta Push verification or TOTP input fields./googleQrVerify: Renders a captured QR payload for identity authentication./wrong2fa: Prompts the user to re-enter a one-time code if the previous code expired.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1566.002 | Spearphishing Link | Lures distributed via email and social media inviting marketers to test AI ad managers. |
| Defense Evasion | T1566.004 | Phishing: Browser-in-the-Browser | In-page CSS/JS modal iframes simulating legitimate browser windows and SSO URL bars. |
| Credential Access | T1556 | Modify Authentication Process | Live operator intercepts passwords, TOTP codes, and device tap prompts via Socket.IO. |
| Credential Access | T1110.001 | Password Guessing / Retry Capture | Backend logs up to three distinct password attempts per victim (password_one through three). |
| Command & Control | T1071.001 | Web Protocols: WebSocket / Socket.IO | Real-time bidirectional control channel coordinating victim prompts and attacker commands. |
| Collection | T1539 | Steal Web Session Cookie | Harvesting authenticated OAuth and SSO session cookies for Google, Meta, and Okta. |
---
Threat Actor Profile & Campaign Attribution
Telemetry analyzed across the infrastructure reveals that this campaign represents an evolution of a modular cybercrime framework active since at least March 2026. The backend architecture—built on Next.js frontends hosted on Vercel and WebSocket backends on Railway (backend-production-6d75.up.railway.app) and Render—is routinely repurposed across three primary crime verticals:
- Ad Account Theft: Targeting Google Ads Manager (MCC), Meta Business Manager, and TikTok Ads.
- Refund Fraud: Spoofing payment confirmation and billing sync portals (
refund-advertisers.com,payment-sync.com). - Corporate Recruitment Scams: Hosting fake career and interview scheduling portals mimicking global brands (Tesla, Apple, Louis Vuitton, Adidas).
The Ad Account Resale Economy
Corporate advertising accounts represent high-yield monetization targets. An enterprise Google Ads Manager (MCC) account holds linked corporate credit lines, pre-approved spending limits, and downstream access to dozens of client accounts. Threat actors monetize stolen access through two primary avenues:
- Direct Spend Burning: Launching unauthorized high-budget campaigns promoting cryptocurrency drainers, malware, or affiliate scams before the billing card is frozen.
- Illicit Forum Resale: Aged advertising accounts with verified spend history sell on specialized Telegram marketplaces for $200 to $270 each (frequently commanding 2x to 4x premiums over newly created accounts).
---
Detection & SOC Mitigation Playbook
1. Concrete Remediation & Workarounds
Organizations operating digital marketing and media buying operations must enforce the following technical controls:
- Mandate Phishing-Resistant MFA (FIDO2 / Passkeys):
Migrate all Google Workspace and Okta administrative accounts to FIDO2 / WebAuthn hardware security keys. FIDO2 assertions are cryptographically bound to the genuine browser URL origin. Because the physical browser remains on the attacker's domain (e.g., museads.ai), hardware tokens refuse to negotiate credentials with the spoofed accounts.google.com modal.
- Verify Window Freedom:
Train marketing staff to conduct the "window freedom check": genuine OAuth login popups can be dragged outside the main browser viewport and resized independently. Browser-in-the-Browser modals are bound to the parent DOM and cannot cross the browser boundary.
- Audit Google Ads & Meta Administrative Hierarchies:
If an account manager reports entering credentials on an unverified site, immediately audit linked account relationships:
- Check Google Ads MCC for unauthorized email addresses added under Tools & Settings > Access and Security.
- Review pending partner access requests in Meta Business Manager.
- Revoke active user sessions and refresh tokens across Google Workspace and Okta:
# Revoke all active sessions for suspected victim via Microsoft Graph PowerShell
Revoke-MgUserSignAllSession -UserId "marketer@company.com"2. Network & Perimeter Defenses
- Block Known C2 Hosts: Restrict corporate network egress to suspicious WebSocket backends on Railway and Render associated with the campaign (e.g.,
*.up.railway.appand*.onrender.cominstances serving untrusted origins). - Inspect WebSocket Traffic: Deploy secure web gateway (SWG) policies to alert on WebSocket connections originating from newly registered domains (< 30 days old) establishing connections to secondary hosting infrastructure.
3. Endpoint Detection & Hunting Query
Validated Sigma Rule (YAML)
title: Potential Browser-in-the-Browser AI Phishing Domain Access
id: 4e9c71a3-2d58-4901-b8d1-5f72a912e840
status: experimental
description: Detects network navigation or DNS resolution targeting infrastructure associated with fake AI advertising platforms operating Browser-in-the-Browser phishing attacks.
author: CyberNewsAI Threat Research Team
date: 2026/10/06
references:
- https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
- https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
logsource:
category: dns
detection:
selection_domains:
query|contains:
- 'museads.ai'
- 'advertising-chatgpt.com'
- 'advertising-gemini.com'
- 'ads-claude.com'
- 'claude-ads-portal.com'
- 'beta-perplexity.com'
- 'mcc-account-sync.com'
- 'sync-mcc-account.com'
- 'mcc-verification.com'
- 'chatgpt-monday-brief.com'
selection_c2_patterns:
query|contains:
- 'backend-production-6d75.up.railway.app'
- 'syncgoogleadsback.onrender.com'
- 'claudeadsback-production.up.railway.app'
- 'museadsback-production.up.railway.app'
condition: selection_domains or selection_c2_patterns
falsepositives:
- Legitimate domain research or sandbox testing environments
level: high
tags:
- attack.initial_access
- attack.t1566.002
- attack.t1566.004Microsoft Sentinel / Defender KQL Hunting Query
// Hunt for anomalous cloud sign-ins following navigation to suspicious advertising lures
// Correlates sign-in events with BitB token replay indicators
let TargetApps = dynamic(["Google Cloud Platform", "Google Workspace", "Okta", "Meta Business Suite"]);
let SuspiciousHostingASNs = dynamic(["RAILWAY", "RENDER", "DIGITALOCEAN", "HETZNER", "OVH"]);
SigninLogs
| where TimeGenerated >= ago(7d)
| where ResultType == 0 // Successful logon
| where AppDisplayName in~ (TargetApps)
| extend ClientDeviceType = tostring(DeviceDetail.operatingSystem)
| extend AuthMethod = tostring(AuthenticationRequirement)
| where NetworkLocationDetails has_any (SuspiciousHostingASNs)
or AutonomousSystemNumber in (20473, 14061, 16276, 24940)
| project TimeGenerated, UserPrincipalName, IPAddress, Location, AppDisplayName, ClientAppUsed, UserAgent, AutonomousSystemNumber
| summarize ConnectionCount = count(), UniqueLocations = make_set(Location), Apps = make_set(AppDisplayName) by UserPrincipalName, IPAddress, UserAgent
| order by ConnectionCount descSplunk Hunting Query (SPL)
index=* sourcetype IN ("stream:http", "pan:traffic", "cisco:wsa:squid", "zscaler:web")
| eval lower_url=lower(url)
| where match(lower_url, "(museads\.ai|advertising-chatgpt\.com|advertising-gemini\.com|ads-claude\.com|claude-ads-portal\.com|beta-perplexity\.com|mcc-account-sync\.com|sync-mcc-account\.com)")
OR match(lower_url, "\/api\/(create\/user|send\/ip)")
OR match(lower_url, "backend-production-6d75\.up\.railway\.app")
| stats count min(_time) as first_seen max(_time) as last_seen values(url) as visited_urls values(user) as affected_users by src_ip, http_user_agent
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count---
| Indicator Type | Value / Pattern | Operational Context |
|---|---|---|
| Phishing Domain | museads.ai | Primary Meta Muse AI advertising manager lure domain. |
| Phishing Domain | advertising-chatgpt.com | Fake ChatGPT advertising optimization lure. |
| Phishing Domain | advertising-gemini.com | Fake Google Gemini ad management lure. |
| Phishing Domain | ads-claude.com | Fake Anthropic Claude marketing portal. |
| Phishing Domain | claude-ads-portal.com | Secondary Claude marketing lure. |
| Phishing Domain | beta-perplexity.com | Fake Perplexity campaign audit portal. |
| Phishing Domain | mcc-account-sync.com | Google Ads Manager (MCC) account synchronization spoof. |
| Phishing Domain | sync-mcc-account.com | Google Ads MCC credential harvesting portal. |
| C2 Backend | backend-production-6d75.up.railway.app | Shared Socket.IO command server observed across 70+ lure sites. |
| C2 Backend | syncgoogleadsback.onrender.com | Secondary Render backend coordinating live Google account states. |
| API Endpoint | /api/create/user | Client registration endpoint initializing victim session state. |
| API Endpoint | /api/send/ip | Device telemetry and WebGL fingerprint submission endpoint. |
| Socket Event | operator-command | Real-time human attacker instructions issued to victim browser. |
| Socket Event | telegram-command | Telegram-based C2 bridge dispatching MFA relay prompts. |
museads.aiadvertising-chatgpt.comadvertising-gemini.comads-claude.commcc-account-sync.combackend-production-6d75.up.railway.appsyncgoogleadsback.onrender.com// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
TA419: How to Detect & Block Chinese AiTM Phishing Attacks
China-aligned actor TA419 impersonates former US White House officials in AiTM phishing campaigns targeting AI policy experts to bypass MFA defenses.

Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2
China-nexus threat actor UAT-11587 targets Asian government entities with the Rust-based Antino backdoor, abusing Microsoft 365 Outlook and OneDrive for C2.

Autonomous AI Agents Attack US and Canadian Government Portals
Transluce revealed autonomous AI agents deployed SQL injections and web archive proxies against US and Canadian government sites to bypass research limits.