Fake Ads for Popular AI Tools Used to Steal Logins and MFA Codes, Researchers Say
Security researchers warn that fake ad platforms posing as ChatGPT, Gemini, Claude, Perplexity, Meta Muse and Manus are luring users to phishing sites that mimic browser login windows and capture credentials and multi-factor authentication codes. The operators then attempt real-time sign-ins, putting both personal and corporate accounts at immediate risk.
Attackers are exploiting interest in major AI tools to harvest passwords and multi-factor authentication (MFA) codes, using fake advertising pages and convincing lookalike sites to trick people into handing over their logins.
According to security researchers, the campaigns revolve around fraudulent ad platforms that appear to promote well-known services such as ChatGPT, Google’s Gemini, Anthropic’s Claude, Perplexity, Meta Muse and Manus. When someone clicks these ads, they’re redirected to phishing sites that open what looks like a standard browser login window.
Instead of connecting to a real provider, the fake window records everything the user types, including usernames, passwords and one-time MFA codes. Researchers say the operators don’t just store those details for later. They attempt real-time sign-ins to the victim’s actual accounts while the phishing session is in progress, immediately reusing any MFA code the user enters.
That approach lets attackers get around protections that many people and organizations rely on. A single login entered into one of these spoofed windows can expose email, cloud storage, internal chat tools and any other services linked to the compromised identity. Where AI tools are tied into workplace systems, a stolen login may also open a path to proprietary data or internal resources accessed through the chatbot.
The phishing pages are polished enough to fool many users at a glance. Rather than crude forms, they imitate familiar login dialogs down to logos and interface details associated with major browsers and identity providers. In many cases, the only clues are subtle differences in URLs or missing security indicators in the address bar.
Researchers who detailed the campaign in a report on The Hacker News warn that the combination of fake AI branding and real-time MFA interception makes these attacks particularly dangerous for corporate environments. They recommend that users reach AI services through trusted bookmarks or direct URLs instead of search ads, and that organizations treat any unexpected login prompt with caution.
How widely these fake AI ads appear across major ad networks, and whether providers move to block them more aggressively, will help determine how long this particular tactic remains effective.
Sources
- OSINT