← Blog · · df00tech

Fake AI Chatbot Sites Used to Hijack Ad Accounts via Browser-in-Browser MFA Theft

security-news campaign

What Happened

According to BleepingComputer, a campaign is targeting advertising account managers with fake websites impersonating ChatGPT, Gemini, Claude, and Perplexity. The sites are reported to use browser-in-browser (BitB) techniques to harvest login credentials and intercept multi-factor authentication (MFA) codes, with the goal of taking over advertising accounts.

Why It Matters

Advertising accounts are high-value targets: compromise can be used to run fraudulent ad spend, redirect budgets, or pivot into connected business and payment systems. Browser-in-browser attacks are notable because they render a convincing fake login popup inside the legitimate page, making them difficult for users to distinguish from real OAuth/SSO prompts — and effective even against accounts protected by MFA. Anyone managing ad platforms, marketing teams, or agencies evaluating AI tools is a plausible target.

What Defenders Should Watch For

  • Educate staff who manage ad accounts that a browser popup asking for AI-tool login credentials, especially one appearing over an unfamiliar or typo-adjacent domain, should be treated with suspicion — a BitB window cannot be dragged outside the parent browser window, which is a quick tell.
  • Hunt for lookalike/typosquat domains referencing ChatGPT, Gemini, Claude, or Perplexity in DNS and proxy logs, and in ad-click/referral traffic.
  • Review sign-in and OAuth consent logs for advertising platform accounts for anomalous logins or new MFA device registrations.
  • Favor phishing-resistant authentication (FIDO2/hardware security keys) for ad platform accounts, since BitB and similar techniques are specifically designed to defeat OTP- and push-based MFA.
  • Prefer accessing AI tools via bookmarked or directly-typed URLs rather than search/ad results, and verify TLS certificate details on any login prompt.

Developing Story

This item is based on initial reporting and does not yet include a CVE, confirmed indicators of compromise, or named threat actor attribution. Details may evolve as more information becomes available. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.