Researchers at the browser-security company Island described a phishing operation that uses counterfeit ChatGPT, Gemini, Claude and Perplexity pages to take over advertising accounts, BleepingComputer reported on 6 October 2026. The activity has been traced back to March [1].
Background
A browser-in-the-browser (BitB) attack draws a fake browser window, including an address bar, inside a web page. The window looks like a genuine sign-in pop-up from a provider such as Google, but it is part of the page and not a separate window.
Findings
According to the report, the pages invite visitors to connect an account to a fake AI product. A forged login window displays “accounts.google.com” in its address bar. After credentials are entered, human operators take over and may ask repeatedly for the password, SMS codes, authenticator codes or an Okta push approval [1].
The targets are ad account managers, media buyers and agency administrators, including people who hold access to several clients’ accounts. Compromised accounts can be used to spend available balances on fraudulent campaigns or be resold [1]. Other lures include fake recruitment and refund pages. The operators’ Telegram channel received “hundreds of victim submissions”, which the report says does not necessarily equal successful compromises [1].
The kit adapts its interface to Windows, macOS, iOS and Android, including browser styling and dark mode. It rebuilds the provider’s interface locally and collects credentials and MFA state through its own APIs, rather than relaying a real login. The infrastructure uses a Next.js and Socket.IO stack with Vercel front ends and Railway or Render back ends, and researchers followed it through exposed GitHub repositories [1].
Implications for people who use a Mac
The campaign is aimed at people who manage advertising accounts, but the technique works against anyone who signs in to a service through a pop-up. A Mac gives no protection by itself, as the kit is built to look native on macOS. The report notes a practical check: the fake window is an element of the page, so it cannot be dragged outside the browser window or resized the way a real OAuth pop-up can [[1]](${BC}).
Recommendations
- Open AI tools from a bookmark or by typing the address, not from an advertisement, message or recruitment link.
- When a sign-in pop-up appears, try to drag it beyond the browser window; a window that cannot leave the page is fake.
- Do not approve a push notification or enter an MFA code that was not prompted by a sign-in you started yourself.
- Where an account is shared across clients, use a phishing-resistant sign-in method if the provider offers one, and review account access regularly.
- If credentials were entered on a suspect page, change the password and revoke active sessions from the provider’s own site.
Relevance to FireAI
FireAI is a firewall for one Mac. When the optional threat lists are turned on, FireAI downloads public lists, including Phishing Army and OpenPhish, once a day and can block a match that a list confirms; the traffic itself is never sent to the lists. A newly built fake site is unlikely to appear on a list at first. FireAI does not inspect web pages, cannot recognise a forged login window and does not prevent a user from typing credentials into a page.
Limitations
This account rests on BleepingComputer’s report of Island’s findings. The number of victims, the loss amounts and the identity of the operators are not stated, and the report counts submissions to a Telegram channel, not confirmed compromises [1].
To see where a Mac connects, download FireAI and try it free for 17 days. FireAI is made by HisnLabs.