Back to Intelligence

Fake ChatGPT, Gemini, Claude, and Perplexity Sites Steal Ad Accounts and MFA Codes — Detection and Defense Guide

SA
Security Arsenal Team
October 6, 2026
12 min read

A newly identified phishing campaign is targeting advertising account managers by impersonating the AI tools they use every day. Attackers are standing up convincing clones of ChatGPT, Google Gemini, Anthropic Claude, and Perplexity login pages, then harvesting not just usernames and passwords but multi-factor authentication codes in real time — effectively neutralizing MFA as a control. The campaign leverages browser-in-the-browser (BitB) techniques, where a fake authentication window is rendered inside the legitimate browser tab using HTML, CSS, and JavaScript, complete with a spoofed address bar showing the "real" URL.

The targeting here is deliberate and financially motivated. Ad account managers hold the keys to Google Ads, Meta Ads Manager, and similar platforms — accounts with attached payment methods, established spend history, and trusted domain reputations. A hijacked ad account is immediately monetizable: malvertising, credit card fraud, and laundering scam traffic through aged, trusted advertiser profiles. If your organization spends money on digital advertising, or manages ad spend for clients, you are in scope for this campaign.

This post breaks down the attack chain, provides production-ready detection content for your SOC, and lays out the remediation steps that actually close the gap — because SMS and TOTP MFA will not save you here.

Technical Analysis

Attack Chain

The campaign follows a well-worn but increasingly polished credential phishing pattern, tuned specifically for the AI-assistant audience:

  1. Lure delivery: Victims are directed to fake AI portal pages through malvertising, search engine poisoning, SEO manipulation, and direct phishing emails. The pages imitate the landing and login flows of ChatGPT, Gemini, Claude, and Perplexity — brands that knowledge workers, including ad operations staff, now authenticate to multiple times per day.

  2. Browser-in-the-browser (BitB) window: When the victim clicks "Sign in," the page renders a fake popup window built entirely in HTML/CSS/JS. The spoofed window displays a legitimate-looking URL (e.g., accounts.google.com or chat.openai.com) in a fake address bar. Because the address bar is part of the page content rather than the browser chrome, trained users who "check the URL" still get fooled. The only reliable tell is that the fake window cannot be dragged outside the bounds of the parent browser window.

  3. Credential and MFA interception (AiTM-style relay): Credentials entered into the fake window are relayed to the legitimate service in real time — an adversary-in-the-middle pattern. When the real service challenges for MFA, the victim is prompted on the phishing page and enters their TOTP or SMS code, which the attacker immediately replays to complete authentication and capture the session token. This is why standard MFA fails: the attacker doesn't need to defeat the second factor, they just need the victim to hand it over within its 30-second validity window.

  4. Account monetization: With a valid session, attackers pivot to the victim's advertising accounts — changing recovery emails, adding attacker-controlled users with admin roles, and launching fraudulent ad campaigns before the victim notices.

Why This Works Against Ad Account Managers

Ad operations staff are a high-value, high-visibility target class:

  • They authenticate constantly to a rotating set of SaaS tools, making login fatigue and muscle-memory credential entry the norm.
  • Their accounts are money. An aged Google Ads or Meta Business account with clean history and an attached payment method sells at a premium and can push scam ads at scale before platform trust-and-safety systems react.
  • They often work under deadline pressure, clicking through login prompts quickly to resolve campaign issues — exactly the condition BitB attacks exploit.

Exploitation Status

This campaign is confirmed active in the wild with victims reported. There is no CVE involved — this is social engineering and web-based deception, not a software vulnerability. No patch is coming. The defensive burden falls entirely on identity architecture, browser hygiene, DNS/proxy filtering, and user behavior.

Technical Indicators and Observable Behaviors

From a defender's standpoint, the campaign produces observable artifacts at several layers:

  • DNS/proxy layer: Lookalike domains mimicking AI brands — typosquats (chatgbt, openai-login, gemini-ai-login, claude-login, perplexity-ai variants), brand-plus-keyword combos (chatgpt-premium, gemini-pro-access), and brand names hosted on unrelated TLDs or free hosting.
  • Browser process layer: Some phishing kits and lure pages open browser windows in app mode (--app=) to suppress the real address bar and make the fake window more convincing — a rare, high-signal command-line flag on endpoints.
  • Post-compromise identity layer: Session token use from anomalous geographies/ASNs, new admin users added to Google Ads or Meta Business Manager, recovery email changes, and sudden ad campaign creation.

Detection & Response

The detections below focus on the highest-fidelity, lowest-noise signals: lookalike domain resolution, app-mode browser launches, and retrospective browser history hunting for compromised users.

Sigma Rules

YAML
---
title: AI Brand Lookalike Domain DNS Query
description: Detects DNS queries for typosquatted or impersonation domains mimicking ChatGPT, OpenAI, Gemini, Claude, and Perplexity, consistent with the fake AI portal phishing campaign stealing ad account credentials and MFA codes.
references:
  - https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
  - https://attack.mitre.org/techniques/T1566/002/
author: Security Arsenal
date: 2026/04/06
status: experimental
logsource:
  category: dns
detection:
  selection_pattern:
    query|re: '(?i)(chatg[bp]t|chatgpt-|openai[-.]?(login|secure|verify|account)|gemini[-.]?(login|pro|secure|ai[-.]login)|claude[-.]?(login|ai[-.]?login|secure)|perplexity[-.]?(login|ai[-.]?login|pro))'
  filter_legitimate:
    query|endswith:
      - '.openai.com'
      - '.chatgpt.com'
      - '.google.com'
      - '.googleusercontent.com'
      - '.anthropic.com'
      - '.claude.ai'
      - '.perplexity.ai'
  condition: selection_pattern and not filter_legitimate
falsepositives:
  - Legitimate regional CDN or partner domains (review and whitelist per environment)
  - Threat research and brand-monitoring activity from security teams
level: high
---
title: Browser Launched in App Mode to External URL
description: Detects Chrome or Edge launched with the --app flag pointing to an HTTP(S) URL, a technique used by phishing lures to suppress the real address bar and increase the credibility of browser-in-the-browser credential theft windows.
references:
  - https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
  - https://attack.mitre.org/techniques/T1566/
author: Security Arsenal
date: 2026/04/06
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection_image:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\brave.exe'
  selection_cli:
    CommandLine|contains:
      - '--app=http://'
      - '--app=https://'
  condition: all of selection_*
falsepositives:
  - Internal web applications deployed as app-mode shortcuts (inventory and whitelist)
  - Kiosk or digital signage configurations
level: medium
---
title: Web Proxy Request to AI Brand Impersonation URL
description: Detects web proxy requests where the URL contains AI brand keywords combined with authentication-related paths on non-official domains, consistent with credential phishing pages impersonating ChatGPT, Gemini, Claude, or Perplexity login flows.
references:
  - https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
  - https://attack.mitre.org/techniques/T1557/
author: Security Arsenal
date: 2026/04/06
status: experimental
logsource:
  category: proxy
detection:
  selection_brand:
    url|re: '(?i)(chatgpt|openai|gemini|claude|perplexity)'
  selection_auth:
    url|contains:
      - 'login'
      - 'signin'
      - 'auth'
      - 'verify'
      - 'account'
  filter_official:
    url|contains:
      - 'openai.com'
      - 'chatgpt.com'
      - 'google.com'
      - 'anthropic.com'
      - 'claude.ai'
      - 'perplexity.ai'
  condition: all of selection_* and not filter_official
falsepositives:
  - AI news, review, or tutorial sites containing brand names in URLs (tune with domain allowlist)
level: medium

KQL (Microsoft Sentinel / Defender)

This hunt surfaces endpoints that resolved or connected to AI-brand lookalike domains — your starting population for identifying potentially compromised ad account managers. It intentionally excludes the official domains to keep the result set actionable.

KQL — Microsoft Sentinel / Defender
// Hunt: Connections to AI-brand lookalike domains (fake ChatGPT/Gemini/Claude/Perplexity portals)
// Run over the last 14 days; pivot to DeviceProcessEvents and IdentityLogonEvents for exposed hosts/users
let OfficialDomains = dynamic(["openai.com","chatgpt.com","google.com","googleapis.com","googleusercontent.com","anthropic.com","claude.ai","perplexity.ai"]);
let BrandPattern = @"(?i)(chatgpt|chatgbt|openai|gemini|claude|perplexity)";
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where isnotempty(RemoteUrl)
| where RemoteUrl matches regex BrandPattern
| extend RemoteUrlLower = tolower(RemoteUrl)
| where not(RemoteUrlLower has_any (OfficialDomains))
| where RemoteUrlLower has_any ("login","signin","auth","verify","account","secure","premium","pro")
   or RemoteUrlLower matches regex @"(?i)(chatgbt|gpt[-.]?(login|secure)|openai[-]|gemini[-]|claude[-]|perplexity[-])"
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Connections=count(), RemoteIPs=make_set(RemoteIP), URLs=make_set(RemoteUrl)
    by DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName
| order by LastSeen desc;
// Secondary hunt: browser processes launched with --app= to suppress the address bar (BitB facilitation)
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName in~ ("chrome.exe","msedge.exe","brave.exe")
| where ProcessCommandLine has_any ("--app=http://","--app=https://")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by TimeGenerated desc;

Velociraptor VQL

This artifact performs retrospective browser history triage — the fastest way to confirm whether a specific user actually visited a fake AI portal and entered credentials. Deploy it against the hosts flagged by the DNS/proxy hunts above, or fleet-wide for ad ops team members.

VQL — Velociraptor
-- Artifact: Hunt browser history for AI-brand lookalike phishing sites
-- Targets Chrome and Edge history databases for visits to fake ChatGPT/Gemini/Claude/Perplexity portals
LET history_files = SELECT FullPath
FROM glob(globs=[
  'C:/Users/*/AppData/Local/Google/Chrome/User Data/*/History',
  'C:/Users/*/AppData/Local/Microsoft/Edge/User Data/*/History'
])

LET hits = SELECT * FROM foreach(
  row=history_files,
  query={
    SELECT FullPath AS HistoryDB,
           url AS VisitedURL,
           title AS PageTitle,
           timestamp(epoch=visit_time / 1000000 - 11644473600) AS VisitTimeUTC,
           visit_count AS VisitCount
    FROM sqlite(file=FullPath,
                query="SELECT url, title, visit_time, visit_count FROM urls WHERE lower(url) REGEXP '(chatgbt|chatgpt[-.]|openai[-]|gemini[-.].*(login|pro|secure)|claude[-.].*login|perplexity[-.].*(login|pro))'")
  })

SELECT HistoryDB, VisitedURL, PageTitle, VisitTimeUTC, VisitCount
FROM hits
WHERE NOT VisitedURL =~ '(?i)(openai\.com|chatgpt\.com|google\.com|anthropic\.com|claude\.ai|perplexity\.ai)'
ORDER BY VisitTimeUTC DESC

Remediation and Triage Script

Run this PowerShell triage script on endpoints belonging to ad account managers or any host flagged by the detections above. It audits the DNS client cache and browser history files for AI-brand lookalike indicators and outputs a flag list for credential-reset prioritization.

PowerShell
# Security Arsenal - Fake AI Portal Phishing Triage Script
# Audits DNS cache and browser history for AI-brand lookalike domains
# Run elevated; output feeds credential/session revocation prioritization

$BrandRegex = '(?i)(chatgbt|chatgpt[-.]|openai[-]|gemini[-.].*(login|pro|secure|ai)|claude[-.].*login|perplexity[-.].*(login|pro))'
$OfficialDomains = @('openai.com','chatgpt.com','google.com','googleusercontent.com','anthropic.com','claude.ai','perplexity.ai')
$findings = @()

# --- 1. DNS client cache audit ---
Write-Host "[*] Auditing DNS client cache for AI-brand lookalike domains..." -ForegroundColor Cyan
$dnsEntries = Get-DnsClientCache -ErrorAction SilentlyContinue
foreach ($entry in $dnsEntries) {
    if ($entry.Entry -match $BrandRegex) {
        $isOfficial = $false
        foreach ($dom in $OfficialDomains) { if ($entry.Entry -like "*$dom") { $isOfficial = $true } }
        if (-not $isOfficial) {
            $findings += [PSCustomObject]@{
                Source = 'DNSCache'; Indicator = $entry.Entry
                Detail = "Resolved to $($entry.Data)"; Risk = 'HIGH'
            }
        }
    }
}

# --- 2. Browser history audit (Chrome/Edge, all profiles) ---
Write-Host "[*] Auditing browser history for fake AI portal visits..." -ForegroundColor Cyan
$historyPaths = @(
    "$env:SystemDrive\Users\*\AppData\Local\Google\Chrome\User Data\*\History",
    "$env:SystemDrive\Users\*\AppData\Local\Microsoft\Edge\User Data\*\History"
)
foreach ($pattern in $historyPaths) {
    foreach ($histFile in (Get-ChildItem -Path $pattern -ErrorAction SilentlyContinue)) {
        $tempCopy = Join-Path $env:TEMP ("hist_" + [guid]::NewGuid().ToString() + ".db")
        try {
            Copy-Item $histFile.FullName $tempCopy -Force -ErrorAction Stop
            $raw = [System.IO.File]::ReadAllText($tempCopy, [System.Text.Encoding]::ASCII)
            $matchesFound = [regex]::Matches($raw, 'https?://[^\s\"''<>]+') | ForEach-Object { $_.Value }
            foreach ($url in $matchesFound) {
                if ($url -match $BrandRegex) {
                    $isOfficial = $false
                    foreach ($dom in $OfficialDomains) { if ($url -like "*$dom*") { $isOfficial = $true } }
                    if (-not $isOfficial) {
                        $findings += [PSCustomObject]@{
                            Source = "BrowserHistory ($($histFile.FullName.Split('\')[2]))"
                            Indicator = $url; Detail = $histFile.FullName; Risk = 'CRITICAL'
                        }
                    }
                }
            }
        } catch { Write-Host "[!] Could not read $($histFile.FullName): $_" -ForegroundColor Yellow }
        finally { Remove-Item $tempCopy -Force -ErrorAction SilentlyContinue }
    }
}

# --- 3. Report and next-step guidance ---
if ($findings.Count -gt 0) {
    Write-Host "`n[ALERT] $($findings.Count) indicator(s) of fake AI portal exposure found:`n" -ForegroundColor Red
    $findings | Sort-Object Risk | Format-Table -AutoSize
    $findings | Export-Csv -Path "$env:TEMP\ai_phishing_triage_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv" -NoTypeInformation
    Write-Host "REQUIRED ACTIONS for flagged users:" -ForegroundColor Yellow
    Write-Host "  1. Immediately revoke all active sessions (Google, Microsoft, Meta, ad platforms)"
    Write-Host "  2. Reset passwords AND re-enroll MFA (assume seed/TOTP compromise)"
    Write-Host "  3. Audit Google Ads / Meta Business Manager for new users, recovery email changes, and unauthorized campaigns"
    Write-Host "  4. Review recent ad spend for fraudulent activity and file platform abuse reports"
} else {
    Write-Host "`n[OK] No AI-brand lookalike indicators found on this host.`n" -ForegroundColor Green
}

Remediation

There is no patch for this threat — it exploits human trust and weak authentication architecture. Remediation is a layered identity and filtering problem:

1. Deploy phishing-resistant MFA — this is the single highest-impact control. TOTP, SMS, and push-based MFA are all replayable in an AiTM/BitB flow. FIDO2 security keys and passkeys are not: the cryptographic challenge is bound to the legitimate origin, so a credential entered on chatgpt-login.evil-example.com produces a signature the real site will reject. Prioritize FIDO2/passkey enrollment for ad account managers, finance, and anyone with payment-method access on ad platforms. Enforce it via conditional access policies — block or require step-up phishing-resistant auth for access to Google Ads, Meta Business Manager, and billing consoles.

2. Block lookalike infrastructure at the DNS and proxy layer. Feed the regex patterns from the Sigma rules above into your protective DNS (e.g., Cisco Umbrella, Infoblox, Quad9-based controls) and web proxy block lists. Subscribe to newly-registered-domain (NRD) feeds and alert on — or outright block — brand-keyword domains registered in the last 30 days. Fake login portals have short lifespans; NRD blocking catches most of them in their operational window.

3. Harden ad platform accounts.

  • Inventory every user with access to Google Ads, Meta Business Manager, TikTok Ads, and LinkedIn Campaign Manager. Remove stale access and enforce least privilege.
  • Enable and monitor admin activity alerts: new user additions, role changes, recovery email/phone changes, and payment method modifications.
  • Set spend anomaly alerts at the platform level — a fraudulent campaign's first symptom is usually a budget spike.

4. Train users on the BitB tell — and verify the training works. The one reliable user-side detection: a fake browser window cannot be dragged outside the parent browser window. Teach ad ops staff to drag any login popup toward the screen edge; if it's constrained inside the tab, it's fake. Better: teach them to never authenticate from a popup or a link at all — navigate directly to the service or use a password manager. Password managers are a powerful passive control here: they will not autofill credentials on a lookalike domain, which is itself a red flag users can be trained to recognize.

5. If exposure is confirmed, move fast. Revoke all sessions (not just password reset — stolen session tokens survive password changes), re-enroll MFA from scratch, audit ad platform account changes going back at least 30 days, dispute fraudulent charges, and file abuse reports with the ad platforms and the phishing domain's registrar/host.

6. Monitor for the downstream crime. Hijacked ad accounts get monetized quickly. Watch for malvertising pointing to your brand's lookalikes, sudden campaign launches in your own accounts, and brand-abuse reports from customers — these are often the first external signal that an ad account in your orbit has been taken over.

The bigger lesson: MFA fatigue and credential phishing have converged on the AI tools your employees trust most. Any control that depends on a user correctly reading an address bar will eventually fail. Architect for that failure — phishing-resistant authentication, origin-bound credentials, and detection at the DNS and identity layers are what actually hold the line.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.