CYBERSECURITY researchers have disclosed a “human-operated phishing platform” that impersonates AI chatbot products such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse and Manus to harvest credentials and MFA codes. The attack uses a browser-in-the-browser BitB technique: a fake sign-in window is drawn inside the real browser with a deceptive address bar showing trusted origins (for example accounts.google[.]com), while the user remains on the attacker’s phishing domain.
The platform fingerprints the victim’s device, transmits data to the attacker via /api/send/ip over Socket[.]IO, and allows an operator to decide which MFA challenge to present next. One site cited is museads[.]ai, launched on 16 September 2026, marketed as an AI ads manager for paid media workflows. Clicking the prominent Connect prompt triggers the BitB flow to capture credentials for Google, Meta, TikTok and Okta.
The operation forms part of a broader phishing platform with three prongs: AI ad-themed credentialing windows; Google Ads–themed refund and payment-confirmation schemes; and recruitment-focused sites for brands such as Tesla, Louis Vuitton, Nike and Adecco. All identified domains reportedly share Next[.]js and Socket[.]IO stacks and communicate with common endpoints; attackers have even exposed earlier platform code in public GitHub repos.
Researchers note the campaign targets agency staff, media buyers and MCC administrators to monetise ad accounts, potentially draining budgets or enabling account sale. Mitigations include phishing-resistant authentication, auditing ad-account changes, and careful vetting of AI integrations before connecting accounts. The report also notes wider abuse of sponsored search and custom GPT content to steer users toward malware delivery.