Impersonated AI Chatbots Lure Ad Managers into Credential‑Harvesting Scheme
Security researchers have identified a coordinated campaign that dupes advertising account managers into surrendering their login details and multi‑factor authentication (MFA) codes. The attackers masquerade as popular generative‑AI services—including ChatGPT, Gemini, Claude and Perplexity—by hosting look‑alike websites that trigger a browser‑in‑browser exploit to capture credentials as users interact with the fake chat interfaces.
The technique hinges on a malicious script that opens a secondary browser window within the victim's session, overlaying the legitimate login page. When the user enters their username, password and the one‑time MFA token, the script silently records the data and forwards it to the attackers, effectively bypassing the additional security layer that MFA is meant to provide.
Targeted victims are primarily professionals who manage large advertising budgets on platforms such as Google Ads, Meta Business Suite and TikTok for Business. These accounts are attractive because they can be used to run costly ad campaigns, and unauthorized access can result in fraudulent spend, data leakage and reputational damage for both agencies and their clients.
The campaign reflects a broader trend of cybercriminals leveraging the popularity of AI chat tools to increase the credibility of phishing lures. By mimicking trusted services that many users consult daily for work‑related queries, the attackers lower the barrier to deception. This evolution underscores the difficulty of defending against social‑engineering attacks that blend cutting‑edge technology with classic credential‑theft tactics.
Experts advising organizations recommend several mitigations: enforce the use of hardware security keys for MFA where possible, educate staff to verify URLs and SSL certificates before entering credentials, and deploy browser security extensions that can detect and block nested browsing contexts. Additionally, monitoring for anomalous login activity on ad platforms can help identify compromised accounts before significant damage occurs.
While the full scope of the operation remains under investigation, early reports suggest that the malicious sites have been active for several weeks and have already harvested credentials from multiple high‑value accounts. Security analysts at BleepingComputer continue to track the infrastructure, urging ad professionals to remain vigilant and to report any suspicious login prompts to their platform providers promptly.
Comments (0)
Be the first to comment.
Join the discussion