Fake AI Ads Phishing Uses Browser-in-the-Browser and Human Operators to Capture Credentials and MFA Codes

Fake AI Ads Phishing Uses Browser-in-the-Browser and Human Operators to Capture Credentials and MFA Codes

伪造 AI 广告钓鱼利用“浏览器内浏览器”技术及人工操作窃取凭据与 MFA 验证码

1. Basic Information

1. 基本信息

Article Title: Behind the Connect Button: The Fake AI Ads Campaign 文章标题: “连接”按钮背后的真相:伪造 AI 广告活动

Publisher: Island 发布方: Island

Publication Date: October 6, 2026 发布日期: 2026 年 10 月 6 日

Report Update Reason: Technical review: Clarified input storage fields and submission limits, distinguished collection capabilities from actual data acquisition and successful authentication, explained what submission counts represent, identified inferred follow-on indicators, and clarified phishing-resistant authentication methods. 报告更新原因: 技术审查:明确了输入存储字段和提交限制,区分了收集能力与实际数据获取及成功认证的区别,解释了提交计数的含义,识别了推断的后续指标,并阐明了防钓鱼认证方法。

Original: Island 来源: Island

Related Sources: BleepingComputer, NIST SP 800-63B-4: Phishing Resistance 相关来源: BleepingComputer, NIST SP 800-63B-4: 防钓鱼指南

Related Malware: None specified 相关恶意软件: 未指定

Related Threat Groups: Unattributed 相关威胁组织: 未归类

Related CVEs: None 相关 CVE: 无

Related Products and Services: Google, Meta, TikTok, Okta authentication, Google Ads/Meta Ads accounts, portals impersonating ChatGPT, Gemini, Claude, Perplexity, Manus, and Muse 相关产品与服务: Google、Meta、TikTok、Okta 认证、Google Ads/Meta Ads 账户,以及冒充 ChatGPT、Gemini、Claude、Perplexity、Manus 和 Muse 的门户网站

Severity: High 严重程度: 高


2. Quick Summary

2. 快速摘要

The phishing pages masquerade as AI advertising management products and draw fake browser windows to collect credentials and MFA codes. Human operators control screen transitions through Socket.IO, prompting victims to re-enter passwords, submit SMS or authenticator app codes, or approve Google or Okta push notifications. 这些钓鱼页面伪装成 AI 广告管理产品,通过绘制虚假的浏览器窗口来收集凭据和 MFA(多因素认证)验证码。人工操作员通过 Socket.IO 控制屏幕跳转,诱导受害者重新输入密码、提交短信或身份验证器应用代码,或批准 Google/Okta 的推送通知。


3. Attack Flow

3. 攻击流程

The same infrastructure is reused for advertising, refund, and recruitment lures. The following flow describes the AI advertising lures analyzed by Island: 同样的架构被重复用于广告、退款和招聘诱饵。以下流程描述了 Island 分析的 AI 广告诱饵:

Attackers lure victims to ad optimization, spending audit, or account connection pages impersonating ChatGPT, Gemini, Claude, Perplexity, Manus, and Muse. When the victim clicks “Connect,” the phishing page draws a fake browser window whose address bar displays a Google or Okta URL. The actual page’s origin remains the phishing domain. 攻击者诱导受害者访问冒充 ChatGPT、Gemini、Claude、Perplexity、Manus 和 Muse 的广告优化、支出审计或账户连接页面。当受害者点击“连接”时,钓鱼页面会绘制一个虚假的浏览器窗口,其地址栏显示 Google 或 Okta 的 URL,但实际页面的源地址仍为钓鱼域名。

The client creates a record via /api/create/user and fingerprints IP, location, screen, and WebGL, sending the data to /api/send/ip. The exposed state object contains identity and three password storage fields, allowing operators to use Socket.IO commands to select the next screen—such as re-entry, SMS codes, authenticator app codes, Google prompts, or Okta pushes. The number of storage fields does not determine the maximum input limit across all implementations. 客户端通过 /api/create/user 创建记录,并对 IP、位置、屏幕和 WebGL 进行指纹识别,将数据发送至 /api/send/ip。暴露的状态对象包含身份信息和三个密码存储字段,允许操作员使用 Socket.IO 命令选择下一个屏幕——例如重新输入、短信验证码、身份验证器代码、Google 提示或 Okta 推送。存储字段的数量并不决定所有实现中的最大输入限制。

Attackers may use the collected information to log in to legitimate services. Island observed hundreds of victim submissions, but has not published the number of successful authentications or unauthorized expenditures on individual accounts. 攻击者可能会利用收集到的信息登录合法服务。Island 观察到了数百次受害者提交记录,但尚未公布成功认证或个人账户未经授权支出的具体数量。


4. Attacker Position and Execution Location

4. 攻击者位置与执行地点

Attackers are remote operators managing the phishing domain and the Next.js/Socket.IO backend. The fake browser is rendered within the victim’s browser, and credentials are sent to the attacker backend rather than AI providers or IdPs. Numerous frontends have been observed on Vercel, and backends on Railway or Render. This does not imply that the hosting providers themselves are the threat actors. 攻击者是管理钓鱼域名和 Next.js/Socket.IO 后端的远程操作员。虚假浏览器在受害者的浏览器内渲染,凭据被发送到攻击者的后端,而非 AI 提供商或身份提供商(IdP)。已观察到大量前端托管在 Vercel 上,后端托管在 Railway 或 Render 上。这并不意味着这些托管服务提供商本身就是威胁行为者。


5. Perspective of Victims and Administrators

5. 受害者与管理员视角

Victims: The page appears as an invitation or account connection for AI advertising management features. The fake window displays a lock icon and accounts.google.com, but the outer address bar shows the phishing domain. 受害者: 页面看起来像是 AI 广告管理功能的邀请或账户连接。虚假窗口显示锁形图标和 accounts.google.com,但外部地址栏显示的是钓鱼域名。

Administrators: Connections to AI-related lookalike domains, api.ipify.org / ipapi.co, or Socket.IO traffic to unrelated Railway/Render hosts may appear in close succession from the same device. 管理员: 同一设备可能在短时间内连续出现对 AI 相关仿冒域名、api.ipify.org / ipapi.co 的连接,或指向无关 Railway/Render 主机的 Socket.IO 流量。

Inference: Investigate subsequent compromises if an advertising account shows unknown managers or partners added, lowered privileges for the original owner, or unapproved campaigns and spending. The number of times these were executed in this campaign has not been published. 推断: 如果广告账户显示添加了未知管理员或合作伙伴、原始所有者权限被降低,或出现了未经批准的广告活动和支出,请调查后续的入侵情况。此次活动中此类行为的执行次数尚未公布。


6. Success and Failure Conditions

6. 成功与失败条件

Success Conditions: The victim reaches the lure and enters credentials via “Connect” without checking the outer real origin. The operator keeps the victim on the waiting screen and selects the appropriate MFA challenge while reviewing the input values and legitimate login results. Account takeover of legitimate services additionally requires that the obtained credentials and MFA materials are valid and satisfy the authentication and device requirements of the legitimate service. Submitting credentials alone does not determine a successful takeover. 成功条件: 受害者访问诱饵页面并通过“连接”输入凭据,且未检查外部真实的源地址。操作员将受害者停留在等待屏幕上,并在审查输入值和合法登录结果的同时选择适当的 MFA 挑战。接管合法服务还需要获取的凭据和 MFA 材料有效,并满足合法服务的认证和设备要求。仅提交凭据并不代表成功接管。

Failure Conditions: Confirming the existence of betas, advertising products, or connectors from the vendor’s official site and avoiding direct connections from invitation links. Enforcing phishing-resistant authentication bound cryptographically to the legitimate service domain, such as WebAuthn/FIDO2 passkeys or security keys. Hardware types alone do not satisfy this property if relying solely on manually entered OTP methods. Blocking and detecting lookalike domains, IOCs, the combination of /api/create/user or /api/send/ip, and external Socket.IO backends. 失败条件: 从供应商官方网站确认测试版、广告产品或连接器的存在,并避免直接通过邀请链接连接。强制执行与合法服务域名进行加密绑定的防钓鱼认证,例如 WebAuthn/FIDO2 密钥或安全密钥。如果仅依赖手动输入的 OTP 方法,单纯的硬件类型无法满足此安全性。拦截并检测仿冒域名、IOC、/api/create/user 或 /api/send/ip 的组合以及外部 Socket.IO 后端。


7. What Happens Upon Success

7. 成功后的后果

Google, Meta, TikTok, and Okta credentials and MFA codes are passed to the attacker. If an ad manager account is compromised, the impact may spread to billing profiles, linked users, and campaigns across multiple clients. In recruitment lures, work identities are entered, potentially leading to intrusions into email, files, and SaaS applications. Public information does not confirm the number of individual account takeovers, unauthorized expenditures, or subsequent compromises. Google、Meta、TikTok 和 Okta 的凭据及 MFA 验证码被传递给攻击者。如果广告管理账户被入侵,影响可能扩散至账单资料、关联用户以及多个客户的广告活动。在招聘诱饵中,受害者输入的办公身份信息可能导致电子邮件、文件和 SaaS 应用被入侵。公开信息尚未确认个人账户接管、未经授权支出或后续入侵的具体数量。


8. Observable Logs

8. 可观测日志

Email: Check for AI advertising product/beta invitations, links prompting account connection, and mismatches between displayed brands and link domains. 电子邮件: 检查 AI 广告产品/测试版邀请、提示账户连接的链接,以及显示品牌与链接域名不匹配的情况。

Proxy / SWG / DNS: Check for close-succession traffic to IOC domains, api.ipify.org, ipapi.co, Railway/Render backends, /api/create/user, and /api/send/ip. 代理 / SWG / DNS: 检查是否存在对 IOC 域名、api.ipify.org、ipapi.co、Railway/Render 后端以及 /api/create/user 和 /api/send/ip 的连续流量。

Endpoint / EDR: Focus on communication within the browser process. Preserve browser history, cache, and network telemetry without assuming downloads or child processes. 终端 / EDR: 重点关注浏览器进程内的通信。保留浏览器历史记录、缓存和网络遥测数据,不要预设存在下载或子进程。

Identity / IdP: Check for logins from new devices/IPs immediately after viewing the phishing page, MFA method changes, session issuance, and Google/Okta prompts. 身份 / IdP: 检查在查看钓鱼页面后立即出现的来自新设备/IP 的登录、MFA 方法更改、会话签发以及 Google/Okta 提示。

SaaS / Cloud: Check for the addition of ad account managers/partners, role changes, recovery… SaaS / 云服务: 检查广告账户管理员/合作伙伴的添加、角色变更、恢复……