Researchers Warn Fake ChatGPT and Gemini Sites Are Stealing MFA Codes


chatgpt gemini MFA
Image credit: OpenAI, Google

Fake AI sites steal advertising accounts and MFA codes by impersonating popular services including ChatGPT, Gemini, Claude, and Perplexity.

Researchers from Island uncovered a phishing campaign targeting agency employees, media buyers, and administrators who may have access to multiple client advertising accounts.

Attackers can use compromised accounts to launch fraudulent advertising campaigns or resell access to other cybercriminals.

Fake Google login windows hide inside the browser

The campaign uses browser-in-the-browser phishing to display a fake Google sign-in window inside the original webpage.

When victims click a “connect” button, the page shows what appears to be a legitimate OAuth popup with an accounts.google.com address bar. However, the login window is actually an iframe designed to capture credentials.

After a victim enters the phishing flow, a human operator can control the next prompts in real time.

Attackers can request passwords, SMS verification codes, authenticator codes, Google approval prompts, Okta push notifications, or QR codes depending on the account they are trying to compromise.

Campaign also targets Google, Meta, TikTok, and Okta

The phishing platform supports fake authentication flows for Google, Meta, TikTok, and Okta.

Unlike reverse-proxy phishing kits, the campaign recreates provider login interfaces locally and sends stolen credentials and MFA information through its own APIs.

Researchers linked the fake AI sites to a broader phishing operation that also uses fake recruitment and refund pages.

Several related sites share Next.js and Socket.IO infrastructure, while many use Vercel for their frontends and Railway or Render for backend services.

Misconfigured public GitHub repositories also exposed older attacker source code, allowing researchers to trace the operation back to March.

A Telegram control channel contained hundreds of victim submissions, although that does not necessarily mean every submitted account was successfully compromised.

How to spot the fake login window

Users can identify browser-in-the-browser attacks by testing the login popup itself.

A fake BitB login window cannot be dragged outside the original browser window or resized like a genuine OAuth popup. If the supposed login window remains trapped inside the webpage, users should avoid entering credentials.

In other cybersecurity news, rogue OpenAI agents edited Wikimedia, Nikkei suffered Microsoft 365 and Google Workspace breaches, and Google paused its OSS vulnerability reports program.

Via BleepingComputer

More about the topics: ChatGPT, Claude, Gemini, perplexity, Phishing

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages