Researchers have disclosed an active, human-operated social engineering platform that impersonates advertising and business products tied to the most popular AI chatbots on the market — Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. The fake portals claim to offer campaign optimization, advertising spend audits, and business-account integrations. Their actual purpose is singular: harvest victim credentials and multi-factor authentication (MFA) codes, then hand them to a human operator who monetizes the access.
This is not a spray-and-pray phishing kit. The 'human-operated' designation matters. It means there is a live adversary on the other end of the interaction — guiding victims through the flow in real time, relaying captured credentials before sessions expire, and adapting the lure based on who bites. That model defeats a significant portion of automated defenses and dramatically shortens the window between initial compromise and account takeover.
The target profile is also deliberate. By impersonating advertising products for AI platforms, the operators are fishing for marketing teams, growth engineers, and small-business owners — users who manage ad budgets, hold OAuth-granted business integrations, and frequently authenticate with corporate Google, Microsoft, and Meta identities. A captured credential in this population often unlocks ad accounts with stored payment methods, connected business tenants, and — where users have reused credentials — corporate SSO.
Defenders need to treat this as an active identity-threat campaign, not a consumer phishing nuisance.
Technical Analysis
Attack Chain (Defender's View)
Based on the disclosed operation, the attack chain unfolds as follows:
-
Lure delivery. Victims encounter the fake portals through advertising-themed content — search ads, sponsored results, or direct outreach — promoting AI-adjacent 'ad management' services. The branding leans heavily on the legitimacy of ChatGPT, Gemini, Claude, Perplexity, Meta Muse, and Manus. Lookalike domains typically combine the AI brand with business keywords:
*-ads,*-business,*-campaign,ads-*, or similar constructions. -
Fake product portal. The landing pages present plausible SaaS functionality: campaign optimization dashboards, ad spend audits, and — critically — 'connect your business account' flows. This is the pivot point where the scam transitions from brand impersonation to credential theft.
-
Credential and MFA capture. When the victim attempts to link their account, they are presented with authentication forms for Google, Microsoft, Meta, or the AI platform itself. The infrastructure captures the username and password, then — consistent with adversary-in-the-middle (AiTM) phishing tradecraft — prompts for and relays the MFA code in real time. Because a human operator is driving the backend, the MFA code is replayed within its validity window, defeating TOTP, SMS, and push-based MFA. The end result is typically a stolen authenticated session (session cookie/token theft), not just a password.
-
Monetization. Captured sessions are used to access ad accounts, pivot into connected business tenants, abuse stored payment instruments, or resell access. Where the victim authenticated with a corporate identity, the operator now holds a valid session inside that organization's cloud environment.
Why MFA Alone Won't Save You
The defining technical characteristic of this campaign is real-time MFA relay. Any MFA method that produces a code or approval a human can read and retype — SMS OTP, TOTP authenticator apps, push approvals without number matching — is relayable. The only authentication factors that structurally resist AiTM relay are phishing-resistant credentials bound to the origin: FIDO2 security keys, Windows Hello for Business, and passkeys. These cryptographically verify the relying party's domain, so a credential presented to a lookalike domain simply will not complete.
Exploitation Status
- Status: Confirmed active, in-the-wild campaign operated as a platform.
- Operator model: Human-operated (live adversary interaction), not fully automated kit.
- CISA KEV: Not applicable — no CVE is associated with this campaign; this is social engineering and infrastructure abuse, not software exploitation.
- Attribution: Not publicly attributed to a named threat actor at time of writing.
Affected Population
Any organization whose employees manage digital advertising, use AI chatbot platforms for business, or authenticate corporate identities (Google Workspace, Microsoft Entra ID, Meta Business) against third-party 'AI tools.' Marketing, growth, and small-business operations roles are the highest-risk population.
Detection & Response
The detection strategy for an AiTM credential-harvesting campaign rests on three pillars: (1) catching the lookalike infrastructure at the DNS/proxy layer, (2) catching the post-compromise identity anomalies (token replay, impossible travel, anomalous session characteristics), and (3) auditing endpoints for evidence of exposure. The rules below target each pillar.
Sigma Rules
---
title: DNS Query to AI Brand Lookalike Ad-Themed Domain
id: 3f9c1e74-8b2a-4d5e-9c17-6a4b8f2d1e03
status: experimental
description: Detects DNS resolutions for domains combining major AI chatbot brands with advertising/business keywords, consistent with fake ChatGPT/Gemini/Claude ad portal infrastructure used for credential and MFA harvesting.
references:
- https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
- https://attack.mitre.org/techniques/T1566/002/
author: Security Arsenal
date: 2026/10/24
tags:
- attack.initial_access
- attack.t1566.002
- attack.t1583.001
logsource:
category: dns
product: windows
detection:
selection_brand:
- 'chatgpt'
- 'openai'
- 'gemini'
- 'claude'
- 'anthropic'
- 'perplexity'
selection_keyword:
- '-ads'
- 'ads-'
- '-ad-'
- '-business'
- '-campaign'
- '-billing'
- '-promo'
- '-partner'
filter_legit:
- 'openai.com'
- 'chatgpt.com'
- 'google.com'
- 'googleapis.com'
- 'anthropic.com'
- 'claude.ai'
- 'perplexity.ai'
condition: selection_brand and selection_keyword and not filter_legit
falsepositives:
- Legitimate regional or partner domains operated by the AI vendors (maintain an allowlist after verification)
level: high
---
title: Proxy Request to AI-Themed Phishing Portal Keywords
id: 8c2d5a91-4e6f-4b38-a1c9-7d3e5f8b2a46
status: experimental
description: Detects web proxy requests to URLs that pair AI chatbot branding with advertising or account-connection terminology, a pattern associated with fake AI ad portals harvesting credentials and MFA codes.
references:
- https://thehackernews.com/2026/10/fake-chatgpt-gemini-and-claude-ad.html
- https://attack.mitre.org/techniques/T1566/002/
author: Security Arsenal
date: 2026/10/24
tags:
- attack.initial_access
- attack.t1566.002
- attack.credential_access
- attack.t1557
logsource:
category: proxy
detection:
selection_brand:
c-uri|contains:
- 'chatgpt'
- 'openai'
- 'gemini'
- 'claude'
- 'perplexity'
selection_path:
c-uri|contains:
- 'ads'
- 'campaign'
- 'connect-account'
- 'link-business'
- 'spend-audit'
- 'billing'
filter_legit:
c-uri|contains:
- 'openai.com'
- 'chatgpt.com'
- 'google.com'
- 'anthropic.com'
- 'claude.ai'
- 'perplexity.ai'
condition: selection_brand and selection_path and not filter_legit
falsepositives:
- Internal marketing tools with AI-themed names (allowlist by domain after validation)
level: high
Tuning guidance: The brand-plus-keyword conjunction keeps these rules tight. The single highest source of noise will be your own marketing team researching legitimate AI advertising products — when a hit fires, validate the domain's registration age and WHOIS privacy status before dismissing it. Phishing domains in this class are typically days-to-weeks old with privacy-shielded registration.
KQL — Microsoft Sentinel / Defender
This two-part hunt covers the pre-compromise (URL exposure) and post-compromise (session anomaly) phases. The identity query is the critical one: AiTM token theft surfaces as sign-ins with impossible travel, unfamiliar session IDs, or MFA claims satisfied by an unfamiliar method/device shortly after a suspicious URL click.
// Part 1: Users who clicked or received URLs matching fake AI ad portal patterns
let AIBrandKeywords = dynamic(['chatgpt','openai','gemini','claude','anthropic','perplexity']);
let AdKeywords = dynamic(['-ads','ads-','-business','-campaign','-billing','spend-audit','connect-account']);
let Lookback = 14d;
union (UrlClickEvents | where TimeGenerated > ago(Lookback) | project TimeGenerated, Url, AccountUpn, Workload, IsClickedThrough),
(EmailUrlInfo | where TimeGenerated > ago(Lookback) | project TimeGenerated, Url, AccountUpn=RecipientEmailAddress, Workload= "Email", IsClickedThrough=int(0))
| extend UrlLower = tolower(Url)
| where AIBrandKeywords any (UrlLower has (_)) or AdKeywords any (UrlLower has (_))
| where UrlLower has_any (AIBrandKeywords) and UrlLower has_any (AdKeywords)
| where UrlLower !has "openai.com" and UrlLower !has "chatgpt.com" and UrlLower !has "google.com"
and UrlLower !has "anthropic.com" and UrlLower !has "claude.ai" and UrlLower !has "perplexity.ai"
| summarize FirstSeen=min(TimeGenerated), Clicks=count() by Url, AccountUpn
| order by Clicks desc;
// Part 2: Post-compromise identity anomalies — successful sign-ins with MFA satisfied
// from a new location/device within 24h of a suspicious URL exposure
let SuspiciousSignins =
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| extend MfaDetail = tostring(AuthenticationDetails[0].authenticationMethod)
| extend SessionId = tostring(SessionId), DeviceDetail = tostring(DeviceDetail.displayName)
| summarize arg_max(TimeGenerated, *) by UserPrincipalName, IPAddress, SessionId;
SuspiciousSignins
| join kind=leftouter (
SuspiciousSignins
| summarize KnownIPs = make_set(IPAddress) by UserPrincipalName
) on UserPrincipalName
| where KnownIPs !has IPAddress
| project TimeGenerated, UserPrincipalName, IPAddress, Location, AppDisplayName, MfaDetail, DeviceDetail, SessionId, UserAgent
| order by TimeGenerated desc;
For higher fidelity in Part 2, correlate against AADNonInteractiveUserSignInLogs as well — token replay from stolen session cookies frequently appears there first, since the attacker is reusing an existing token rather than performing a fresh interactive login. Also alert on AuditLogs for Consent to application events in the same window; fake 'connect your business account' flows often end in a malicious OAuth consent grant that persists access even after password resets.
Velociraptor VQL
If you have a user who reports interacting with a fake AI ad portal, or your DNS/proxy rules fire on a specific host, this artifact pulls browser history from Chrome and Edge to establish exposure scope — which domains were visited, when, and how many times. That timeline directly informs whether credentials were likely entered.
-- Hunt browser history for visits to AI-brand lookalike ad portal domains
LET HistoryFiles = SELECT FullPath
FROM glob(globs='C:/Users/*/AppData/Local/{Google/Chrome,Microsoft/Edge}/User Data/*/History')
SELECT FullPath AS HistoryDB,
url AS VisitedURL,
title AS PageTitle,
datetime(last_visit_time / 1000000 - 11644473600, 'UnixEpoch') AS VisitTimeUTC,
visit_count AS VisitCount
FROM foreach(
row=HistoryFiles,
query={
SELECT url, title, last_visit_time, visit_count
FROM sqlite(file=FullPath, query='SELECT url, title, last_visit_time, visit_count FROM urls')
WHERE url =~ '(?i)(chatgpt|openai|gemini|claude|anthropic|perplexity).*(ads|campaign|business|billing|spend|connect)'
AND url !~ '(?i)(openai\.com|chatgpt\.com|google\.com|anthropic\.com|claude\.ai|perplexity\.ai)'
})
ORDER BY VisitTimeUTC DESC
Hardening / Triage Script
This PowerShell script performs three actions on a suspected-exposed Windows endpoint: blocks known-pattern lookalike domains at the hosts-file layer as an interim control (DNS-layer blocking at the resolver is the preferred enterprise control), verifies Microsoft Defender SmartScreen and PUA protection are enabled, and flags recently installed browser extensions — a common secondary persistence/abuse vector in these campaigns.
# Fake AI Ad Portal - Endpoint Triage and Hardening
# Run elevated on suspected-exposed hosts
# 1. Verify SmartScreen and phishing protection are enabled
$smartScreen = Get-MpPreference | Select-Object -Property EnableSmartScreen, SmartScreenAppInstallControl
Write-Output "[SmartScreen Status]"; $smartScreen | Format-List
if (-not (Get-MpPreference).EnableSmartScreen) {
Set-MpPreference -EnableSmartScreen $true
Write-Output "[ACTION] SmartScreen re-enabled"
}
# 2. Block confirmed malicious lookalike domains at hosts-file layer (interim control)
# Replace with validated IOCs from your threat intel feed - do NOT block on patterns alone
$hostsPath = "$env:SystemRoot\System32\drivers\etc\hosts"
$blocklist = @(
# Example entries - populate with confirmed IOCs from your IR/CTI team
# "chatgpt-ads.example.com",
# "gemini-business.example.com"
)
foreach ($domain in $blocklist) {
if (-not (Select-String -Path $hostsPath -Pattern $domain -Quiet)) {
Add-Content -Path $hostsPath -Value "0.0.0.0`t$domain"
Write-Output "[ACTION] Blocked: $domain"
}
}
# 3. Inventory Chrome/Edge extensions for suspicious additions
$extPaths = @("$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Extensions",
"$env:LOCALAPPDATA\Microsoft\Edge\User Data\Default\Extensions")
foreach ($p in $extPaths) {
if (Test-Path $p) {
Get-ChildItem $p -Directory | ForEach-Object {
$recent = Get-ChildItem $_.FullName -Recurse -Filter "manifest.json" -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) }
if ($recent) { Write-Output "[REVIEW] Recently modified extension: $($_.FullName)" }
}
}
}
# 4. Export recent DNS cache entries matching AI-ad portal patterns for IR evidence
Get-DnsClientCache | Where-Object { $_.Entry -match '(chatgpt|openai|gemini|claude|perplexity).*(ads|campaign|business|billing)' } |
Export-Csv -Path "C:\IR_AIPortal_DNS_$env:COMPUTERNAME.csv" -NoTypeInformation
Write-Output "[DONE] DNS evidence exported. Correlate with proxy/DNS logs and force credential + session reset if exposure confirmed."
Remediation
There is no patch for social engineering — remediation here is identity-centric and architectural. Prioritize in this order:
1. Treat every exposed identity as fully compromised. If a user entered credentials and an MFA code into one of these portals, a password reset alone is insufficient — the operator likely holds a live session token and possibly an OAuth consent grant. For each confirmed victim:
- Revoke all active sessions and refresh tokens (
Revoke-MgUserSignInSession/ Entra admin center "Revoke sessions"), then reset the password. - Audit
AuditLogsfor OAuth consent grants made in the exposure window and remove any unrecognized service principal permissions. - Review mailbox rules, forwarding settings, and registered MFA methods for attacker-added persistence.
- Check ad platform accounts (Google Ads, Meta Business) for unauthorized users, payment method changes, or launched campaigns.
2. Deploy phishing-resistant MFA to high-risk populations first. Marketing, finance, ad-ops, and anyone managing business ad accounts should be moved to FIDO2 security keys or passkeys immediately, with number matching enforced for any remaining push-based MFA. This is the only control that structurally defeats real-time MFA relay. Where Entra ID is in use, enable Conditional Access token protection (token binding) so stolen session tokens cannot be replayed from attacker infrastructure.
3. Block the infrastructure class, not just the IOCs. Individual phishing domains in this campaign are disposable. Implement resolver-level DNS filtering with category rules for newly registered domains (NRDs) containing major brand names, and tune web proxy policies to flag brand-plus-keyword constructions (*-ads, *-campaign, *-billing) for the affected AI vendors. Feed confirmed domains to your DNS filter, browser isolation, and email security stack simultaneously.
4. Harden email and web delivery paths. Ensure Safe Links / URL rewriting is enabled and in block mode for clicks to NRDs; add the AI-ad-portal keyword pattern to your secure email gateway's URL detonation rules. Train the specific targeted population — ad-ops and marketing — on this exact lure: no legitimate ChatGPT, Gemini, Claude, or Perplexity advertising product asks you to "connect your business account" through a third-party portal or a sponsored search ad.
5. Monitor for downstream abuse for 30+ days. Captured ad accounts are monetized through malvertising and payment fraud; captured corporate identities are resold. Watch for anomalous ad spend, new admin users on business platforms, and sign-ins to the victim identities from hosting-provider ASN space.
6. Report and request takedown. Submit confirmed phishing domains to the impersonated vendors' abuse teams (Google Safe Browsing, OpenAI, Anthropic, and Meta all operate brand-abuse reporting channels), to Microsoft/Google browser safe-browsing feeds, and to the registrar and host of record. Human-operated platforms are sensitive to infrastructure churn — sustained takedown pressure raises their operating cost materially.
The strategic lesson for CISOs: the AI brand boom has created a trusted-brand attack surface that moves faster than vendor brand-protection programs. Any workflow where an employee can be induced to "connect an account" to an AI-branded service is now a credential-theft vector. Phishing-resistant authentication and OAuth consent governance are the controls that hold.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.