Island details a human-operated phishing platform with fake Gemini, Claude, ChatGPT and Muse ad portals that steal ad-account passwords and MFA. It is phishing, not an AI flaw.
A human-operated phishing platform is posing as AI advertising products from Google, Anthropic, OpenAI, Perplexity, Manus and, most recently, Meta. It aims to take over advertising accounts. Island researchers Oleg Zaytsev and Ofek Ronen described it on October 6, 2026. The lures target agency staff, media buyers and manager-account administrators. This is phishing, not a flaw in any of the impersonated AI products, and Island does not attribute the operation to any actor.
What happened
Each fake brand gets its own pitch. ChatGPT promises a Monday Google Ads brief. Gemini promises manager-account (MCC) and linked-client support. Claude gets its own advertising portal. Perplexity offers campaign planning and spend audits, and Manus offers a private Meta integration. Every page leads to the same action, a Connect button. Island says invitation emails pointing victims to these pages have been documented by IRONSCALES and Intezer.
The newest skin followed the news closely. Meta introduced Muse on September 8, 2026 (we covered the earlier Muse Glimmer and Spark models). Island saw museads.ai presenting "Muse Ads" by September 16, eight days later. Island notes its dates are the earliest observations it kept, not the first day each site operated. Island captured the spoofed page on September 19.
From Meta's Muse announcement to a fake Muse Ads site in eight days
Island says it saw "hundreds of victim submissions to the platform, and activity was still ongoing at the time of writing." It gives no exact count.
How it works
How the fake Connect button leads to ad-account takeover
Browser-in-the-Browser. Clicking Connect does not open Google. The page draws a fake Chrome window with a lock icon and an address bar reading accounts.google.com, or an Okta tenant. The real browser stays on the phishing domain. The fake window adapts to Windows, macOS, iOS and Android, and newer builds copy Safari's URL pill, Chrome custom tabs and dark mode. A code comment in the bundle notes that without the frosted-toolbar styling the window "gives away the fake."
Operator panel. On Connect, the client creates a record through /api/create/user, fingerprints the device (IP, location, screen size, WebGL) and sends the profile to /api/send/ip. A Socket.IO channel then carries victim data to a human operator and commands back. The state stores three separate password attempts, so an operator can reject one entry, ask again and keep every value.
MFA challenge selection. The operator picks the next screen for Google, Meta, TikTok or Okta flows. The command set includes requests for another password, an SMS code, an authenticator code, a Google approval prompt, a supplied QR payload or tap number, an Okta push, a "wrong code" rejection, a finish command and a command that suppresses the page for the visitor. Commands arrive as operator-command and telegram-command events. (For another way around MFA, see real-time deepfake fraud.)
Island stresses this is not a classic reverse-proxy kit. The platform rebuilds the provider interface locally and collects credentials and MFA state through its own APIs. Traffic therefore looks like an AI product talking to an unrelated backend.
Infrastructure
The AI ads pages are one of three lanes on a shared Next.js and Socket.IO stack. The other two are Google Ads-themed refund and payment-confirmation pages, and fake recruitment sites for brands such as Tesla, Louis Vuitton, Nike and Adecco. The recruitment lane goes back to at least July 2025 (Island's Figure 7 shows a Tesla page, and the operators' GitHub accounts, such as recruiterid and reudisace), so this is a long-running platform with a new AI skin, not a new kit. Many branches use Vercel-hosted pages with Railway or Render backends. One Railway backend appeared in 73 archived scans across 25 page domains between May 27 and June 20, linking AI-ad, refund and fake-careers pages. The operators also left source code for earlier versions in misconfigured public GitHub repositories.
Island publishes its indicators inline, in Ads, Refund and Recruit groups. They mix phishing domains with Railway and Render backend hostnames. Examples include the typosquat gemimi-ads.com and the lookalike claude-ads.ai.
The list also holds lookalikes for brands Island's prose never names, including adsmistral.com, cursor-ads.com, semrush-ai.com, semrushads-ai.com and sync-tiktok.com. That comes from the indicator list, not from an Island claim that campaigns against those brands were live.
Why ad accounts
An advertising account holds a stored payment method and an approved budget, and a manager account can reach several client accounts. Citing Mimecast, Island says attackers either spend the budget or sell the account, and that aged, clean accounts sell on Telegram for two to four times the price of new ones. Island cites Mimecast putting high-risk-vertical Google Ads accounts at roughly $200 to $270. Recovery can take weeks or months, because attackers add their own administrators and downgrade the owner.
What defenders should do
- Treat any AI "integration" or beta program as an account-access request, and verify it through the vendor's official site.
- Check the outermost browser origin. A page can draw an address bar, lock icon or dialog, but it cannot change the real origin.
- Hunt for the client pattern:
google_uid, repeated password fields,api.ipify.org,ipapi.co,/api/send/ip,/api/create/user, and Socket.IO connections to unrelated Railway or Render hosts. Island also suggests hunting for the control vocabulary itself, such asoperator-command,telegram-commandand the password-retry wording, rather than relying on hosting IPs alone. - Use a passkey or hardware security key for the Google Account sign-in, since origin-bound credentials remove the reusable passwords and one-time codes this platform collects. Then lock down account changes inside Google Ads. Google says all advertisers can set up a passkey, and it may require one for sensitive actions such as account linking updates or user access changes. The Ads "Confirm it's you" passkey is not the same as a Google Account sign-in passkey, so you need both. Admins can turn on "Require passkeys for sensitive actions" (Admin > Account > Security), which blocks SMS, email one-time codes and phone prompts for those actions and cannot be turned off once on. It is rolling out gradually to a subset of advertisers. The "Passkey status" column under Admin > Access and security shows coverage.
- After any exposure, review every reachable client account for new managers or partners, changed recovery details and unapproved campaigns or spend.
Who is exposed
Island writes the lures for agency staff, media buyers and manager-account administrators, so the people most likely to be asked to "connect" an AI tool to an ad account are the ones with the broadest access. For solo advertisers the main risk is the account's card and budget. For an agency, a single manager-account login can reach many client accounts, each with its own billing profile and linked users.
Island names a third group: job applicants lured by the fake recruitment sites. They "may sign in with a work Google or Okta identity, so one stolen login can open their current employer's email, files, and SaaS apps." That is the enterprise exposure, and it reaches well beyond marketing teams. Our inference, not Island's: developer and marketing-technology teams that wire AI assistants into ad platforms will see the same "connect" prompt, and AI logins are already a theft target (see stolen ChatGPT logins).
What is still unclear
- Scale. Island reports "hundreds of victim submissions", which counts form submissions to the platform, not confirmed compromised accounts. No total of hijacked ad accounts is published.
- Indicator totals. Island gives no total for its indicator list. By our count the inline list has 139 entries (114 Ads, 11 Refund, 14 Recruit). One Railway backend appears in all three groups, which leaves 137 unique: 109 domains and 28 Railway or Render backend hosts. The classification is ours.
- Who is behind it. Island does not name an actor, and neither do we.
- Vendor response. No statements from Meta, OpenAI, Anthropic or Google appear in Island's report or in The Hacker News coverage.
- Page revision. Island's post carries no "Updated" date, so wording could still change.