Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

Summary

A new cyberattack campaign is targeting ad account managers by using fake websites impersonating popular AI chatbots like ChatGPT, Gemini, Claude, and Perplexity. These fraudulent sites employ browser-in-browser (BiB) attacks to steal user login credentials and multi-factor authentication (MFA) codes.

IFF Assessment

FOE

This campaign represents a direct threat to defenders by exploiting legitimate user credentials and MFA to gain unauthorized access to sensitive advertising accounts.

Defender Context

This campaign highlights the growing sophistication of phishing and social engineering tactics, especially those leveraging AI-themed lures. Defenders should educate users about the risks of clicking on suspicious links, verify website authenticity, and reinforce the importance of MFA, while also being aware of potential bypass techniques.

Read Full Story →