Island: fake ChatGPT, Gemini, Claude, Perplexity and "Muse Ads" advertising tools run a human-operated browser-in-the-browser phishing platform that steals Google, Meta, TikTok and Okta logins and MFA codes from ad account managers
Browser security company Island published research on 6 October 2026 on a phishing platform dressed up as a range of AI advertising products, from campaign optimisation and spend audits to business-account connections, using the names ChatGPT, Gemini, Claude, Perplexity and Manus. Eight days after Meta launched its Muse AI agent on 8 September, museads.ai appeared (by 16 September) offering a fake "Muse Ads" manager. Every page leads to a Connect button that draws a fake browser window inside the page, with an address bar showing accounts.google.com or an Okta tenant, styled to match Windows, macOS, iOS or Android. Behind it a human operator watches in real time: the platform keeps every password attempt, fingerprints the device, can ask for the password up to three times, then chooses whether to show an SMS or authenticator code request, an Okta push, a Google approval prompt or a QR code, and can reject codes or hold the victim on a waiting screen. It supports Google, Meta, TikTok and Okta sign-in flows. Targets are agency staff, media buyers and administrators whose accounts reach many client ad accounts, which can be drained on fraudulent campaigns or resold. Older source code left in misconfigured public GitHub repositories traced the operation back to March and showed the same kit reused for refund and recruitment lures; Island saw hundreds of victim submissions to its Telegram control channel, and activity was ongoing at publication. Primary: Island; wire: BleepingComputer.
- Product
- Google, Meta, TikTok and Okta accounts of advertising agencies and media buyers
- Versions
- n/a — phishing campaign; no product flaw
- Exploited in Australia?
- unknown
- Patch to
- Use phishing-resistant MFA (passkeys or FIDO2 security keys) for ad, Google Workspace and Okta admin accounts, since operators relay SMS, authenticator and push codes live. Teach staff the quick test for a fake sign-in pop-up: a real window can be dragged outside the browser or resized, a drawn one cannot. Restrict which third-party apps can be connected to ad accounts and manager accounts, review recently granted access, and set spend alerts on client ad accounts.
Primary: Island — Behind the Connect Button: The Fake AI Ads Campaign (6 Oct 2026) · BleepingComputer — Fake ChatGPT, Gemini sites steal advertising accounts, MFA codes (6 Oct 2026)
