Researchers Expose AI Brand Phishing Campaign Targeting Advertisers
Island says the ongoing campaign impersonates ChatGPT, Gemini, Claude and other AI tools, then asks victims to link their Google accounts.
Security researchers at Island have published a report describing an ongoing phishing campaign that impersonates AI brands including ChatGPT, Google Gemini, Claude, Manus and Muse, according to techradar.com.
The campaign targets advertisers and marketing managers with fake AI marketing tools. Once a victim engages, the page asks them to connect their Google account.
Victims are then shown a browser-in-the-browser phishing page that mimics a legitimate login screen such as accounts.google.com. Live human operators follow each victim's login attempt in real time and can fake errors or choose which multi-factor authentication screen appears.
The phishing platform supports workflows for Google, Meta, TikTok and Okta, the researchers said.
Island also found that the operators' source code for earlier versions of the campaign had been left exposed on a misconfigured public GitHub repository.
At the time of writing, the campaign was still ongoing, and researchers said they had observed hundreds of victim submissions.
Quick answers
Which AI brands does the phishing campaign impersonate?
The campaign impersonates ChatGPT, Google Gemini, Claude, Manus and Muse, according to Island's report.
How does the phishing page capture login details?
It presents a browser-in-the-browser page mimicking a legitimate login such as accounts.google.com, while live operators monitor each attempt and can fake errors or select the MFA screen shown.
Is the campaign still active?
Yes. Island said the campaign was still ongoing at the time of writing and that researchers had observed hundreds of victim submissions.