Models & LabsUnited States
Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials
Wiley fisherfolk spin up a new page just days after Meta's AI agent launch
A phishing campaign targeting advertising managers by impersonating Gemini, Claude, ChatGPT, Perplexity, and Manus to steal credentials and multi-factor authentication (MFA) codes has added a fake Muse Ads product to its lure lineup – just eight days after Meta launched its personal AI agent.
Meta announced Muse on September 8, and by September 17, a very convincing website – museads.ai – for a product called Muse Ads that promised to help advertisers reach buyers and run sponsored placements popped up online.
“The operators already had the platform, so adapting it to a new brand can take minutes,” Oleg Zaytsev, lead security researcher at Island, told The Register. “The striking part is how quickly they turned a timely announcement into a credible reason for someone to act. The same platform could then be repackaged around other familiar tasks, from connecting a business tool to claiming a refund or applying for a job.”
The security startup spotted the Muse Ads webpage, and upon digging into the scam uncovered that just the page was new. “Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus,” Zaytsev and fellow Island researcher Ofek Ronen wrote in a blog post published Tuesday.
All of these products served as lures for browser-in-the-browner (BitB) attacks designed to trick agency staff, media buyers, and manager-account administrators into handing over their advertising account credentials – along with stored payment methods and client accounts – to digital thieves.
“For victims, the potential cost is loss of access to an advertising account, unauthorized ad spend, and exposure of linked client accounts,” Zaytsev told The Register.
How the scam works
BitB is a clever phishing technique originally detailed by a researcher called mr.d0x in 2022. It involves building a fake login window directly inside a legitimate one. The fake window looks like the real thing, featuring an address bar, title, and URL, but it's just an overlay to steal users’ credentials.
According to Zaytsev, this one has likely proved very lucrative for its criminal operators, with hundreds of victim submissions to the platform, and activity still ongoing.
“From one frontend alone, we observed submissions involving roughly 200 distinct email addresses over about a month,” he told us. “The operators used the same platform across many similar sites, so we estimate the campaign-wide volume is substantially higher.”
Each phony ad product has its own page, with ChatGPT promising users a Monday Google Ads brief, Gemini offering manager account and linked-client support, Claude an advertising portal, Perplexity pitching campaign planning and spend audits, and Manus providing a private Meta integration.
Each fake product page also has a “connect” button. When the victim clicks “connect,” it opens the browser-in-browser overlay, with a fake address bar showing accounts.google.com, or an Okta tenant to gain the victim’s trust. The real browser, however, stays on the phishing domain and steals credentials when the victim types them in.
A human operator running the campaign sees each submission and chooses what the victim sees and is prompted to do. This includes asking for another password, requesting an SMS or Okta authenticator code to bypass MFA, showing a Google approval code or Okta push request, or displaying a QR code.
The platform supports Google, Meta, TikTok, and Okta workflows, and the browser overlay adapts to whatever the victim runs: Window, macOS, iOS, ot Android, and even mimics Safari’s URL pill, Chrome’s custom tabs, and a dark mode.
And while the researchers told us they haven’t identified the people operating the kit or found a name under which it’s sold, the operators did expose older source code through misconfigured public GitHub repositories that connected this to a campaign to a larger operation.
In addition to the AI ad pages, this operation also used fake refund claims and job recruitment sites as lures with separate builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton.
All of these pages run on one Next.js and Socket.IO stack. Many of the pages also used Vercel frontends with Railway or Render services behind them for state and commands.
“A new brand or polished page doesn’t necessarily mean a new attack. Operators can change the lure quickly, but the workflow still has to move someone onto a site they control, collect credentials, and steer them through authentication,” Zaytsev said.
“Security teams should maintain a continuous baseline of trusted domains, check the real browser address, and connect similar behavior across different sites,” he added. “Attackers can generate a convincing website quickly; building the domain history and reputation of a legitimate service is much harder. AI can help defenders keep pace with AI-generated websites, especially as they become more convincing and appear more quickly.”. ®