Eight days after Meta launched Muse, operators added a fake Muse Ads product to a human-operated phishing platform already impersonating Gemini, Claude, ChatGPT, and Perplexity.

Island security research uncovered a human-operated phishing platform disguised as a portfolio of AI advertising products. Its products ranged from campaign optimization and spend audits to business-account connections. The newest lure, Muse Ads, appeared shortly after Meta announced Muse.
Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain. Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next.
The operators exposed source code for earlier versions of the platform through misconfigured public GitHub repositories, which reveals the operating model behind the pages. While tracking the campaign, we saw hundreds of victim submissions to the platform, and activity was still ongoing at the time of writing. Human operators could hold a victim on a waiting screen, reject a password, choose the next MFA prompt, and redirect the victim when the flow was complete. The same machinery is reused for refund and recruitment lures.
Meta introduced Muse as a personal AI agent on September 8, 2026. Meta's announcement described an agent that could work across the apps people use every day.
By September 16, “museads.ai” was presenting a new product: Muse Ads, described as “Your AI ads manager for paid media workflows.” It promised to help advertisers reach buyers, connect an advertising account, and run sponsored placements.

The danger sat behind the Connect button. A visitor who clicked it and signed in with Google handed that account, and every ad account behind it, to a human operator watching in real time. Only the page was new. Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus.
Every brand gets its own pitch. ChatGPT promises a Monday Google Ads brief. Gemini promises MCC (manager account) and linked-client support. Claude gets its own advertising portal, Perplexity offers campaign planning and spend audits, and Manus offers a private Meta integration.

The copy is written in advertiser shorthand like MCC and ROAS, so a request to connect an account feels routine. Every page leads to the same action: Connect. Invitation emails that send victims to these pages have been documented by IRONSCALES and Intezer.
Clicking Connect does not open Google. The page draws a fake Google window inside itself.
An after-Connect capture shows the real browser still sitting on the phishing domain. Inside it, the page renders a second Chrome window, complete with a lock icon and an address bar reading accounts.google.com.

This technique is known as Browser-in-the-Browser.
The fake browser adapts to whatever the visitor runs, from Windows and macOS to iOS and Android. Newer builds copy the small details as well, like Safari’s URL pill, Chrome’s custom tabs, and a dark mode.
The bundle even contains comments explaining why the fake chrome needs a frosted treatment:
/* Real iOS Safari and Chrome custom tabs use frosted toolbars.
Without this, the chrome looks painted-on and gives away the fake. */
.iab-chrome-translucent {
backdrop-filter: saturate(180%) blur(20px);
}The fake Google window is only the presentation layer. Underneath it is a state machine designed to follow the victim through authentication. A human operator, the attacker running the campaign, can see each submission and decide what the victim sees next.
When the visitor clicks Connect, the client creates a record through /api/create/user. It then fingerprints the device, from IP and location down to screen size and WebGL, and sends the profile to /api/send/ip.
The state object can retain identity details and three separate password attempts:
password_one
password_two
password_threeThis is deliberate retry handling. An operator can reject one entry, ask the victim to try again, and preserve every submitted value.

The platform supports Google, Meta, TikTok, and Okta workflows. Its command vocabulary includes:
/password request another password
/2fa request an SMS code
/authApp request an authenticator code
/googlePrompt show a Google approval prompt
/googleQrVerify display a supplied QR payload
/verifyTap display a supplied tap number
/oktaApprove show an Okta push request
/oktaAuthApp request an Okta authenticator code
/wrong2fa reject the current code
/done complete the flow
/ban suppress the page for the visitorCommands arrive through Socket.IO events such as operator-command and telegram-command. The backend chooses the next screen while the victim is still engaged.
Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs. That makes the traffic look like an AI product talking to an unrelated application backend, rather than a browser session passing through a classic identity-provider proxy.
Under every brand, the application stayed the same. AI ad pages, refund claims, and fake job sites all run on one Next.js and Socket.IO stack. They call the same endpoints and hand the victim to the same operator commands.

The product story changed faster than the underlying flow. Infrastructure was modular: many observed branches used Vercel-hosted pages with Railway or Render services behind them for state and commands.
One backend makes the link concrete. backend-production-6d75.up.railway.app appeared in 73 archived scans across 25 page domains between May 27 and June 20. Its clients ranged from Gemini, OpenAI, and Anthropic ad lures to refund pages and a fake Louis Vuitton careers site. A page selling an AI ads product and a page offering a fake job talked to the same server. It is the clearest link between the lanes.
The retained sequence shows the platform moving through several AI brands during 2026. These are the earliest observations we retained, not the first day each site operated.

The operators exposed older source code through misconfigured public GitHub repositories, which makes the recruitment reuse visible. The recruiterid/teslanewnewne frontend and recruiterid/newnewtesla backend show the same routes and the same three-password retry model, with Telegram wired in as the control channel. A second disposable account, `reudisace`, published related recruitment builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton. The newer AI advertising bundles preserve the same unusual state language and extend the control model with tenant-aware routing and expanded Google and Okta states.

The lures are written for agency staff, media buyers, and manager-account administrators, because an advertising account is a spending account. It carries a stored payment method and an approved budget, and a manager account can reach several client accounts, each with its own billing profile and linked users.

Mimecast’s ad account theft research describes two ways attackers monetize a stolen account: spend its budget on their own campaigns, often a short-lived gain, or sell it. Aged accounts with a clean spend history sell on Telegram for 2 to 4 times the price of new ones, complete with escrow and warranties. Google Ads accounts for high-risk verticals list at roughly $200 to $270.
For the victim, the card is the easy part: they can remove it within hours. Getting the account back is not. Attackers typically add their own administrators and downgrade the legitimate owner, and recovery can take weeks or months while the account keeps serving ads. For a manager account, the damage reaches the agency’s clients.
The recruitment lane targets a different victim. Someone applying for a job is usually employed somewhere else and may sign in with a work Google or Okta identity, so one stolen login can open their current employer’s email, files, and SaaS apps.
Phishing pages are now built to order. Each one in this campaign poses as a believable product, with its own brand, pitch, and sign-in flow. They also move with the news. Muse Ads appeared within eight days of Meta announcing Muse, so a brand-new product launch is exactly when a fake one looks most convincing. AI makes that pace possible, and turning a phishing idea into a polished, branded page now takes minutes.
The browser is where the invitation, product, identity flow, and business application meet. Island is built to give organizations visibility and control across that entire path.
[Ads]
account-sync-data.com
ads-claude-beta.com
ads-claude.com
ads-team-openai.com
adsmistral.com
advertising-chatgpt.com
advertising-gemini.com
ai-ads-platform.com
ai-brand-safety.com
anthropic-ads-beta.com
anthropic-ads-marketing.com
anthropic-ads.com
anthropic-beta-ads.com
anthropic-crm-1.com
anthropic-sponsored.com
beta-anthropic.com
beta-chatgpt.com
beta-gemini-ads.com
beta-manus.com
beta-perplexity.com
business-gemini.com
chatgpt-advertise.com
chatgpt-advertisement.com
chatgpt-beta.com
chatgpt-brief.com
chatgpt-briefing.com
chatgpt-monday-brief.com
claude-ads-beta.com
claude-ads-invitations.com
claude-ads-portal.com
claude-ads.ai
claude-advertisement.com
claude-advertisers.ai
claude-advertisers.com
claude-beta-invite.com
claude-beta.com
cursor-ads.com
escrow-ads.com
gemimi-ads.com
gemini-ads-ai.com
gemini-ads-invite.com
gemini-ads-team.com
gemini-ads.ai
gemini-advertisers.com
gemini-beta-invitations.com
gemini-beta-invites.com
gemini-business.com
gemini-google-ads.com
gemini-invitation.com
gemini-invitations.com
gennini-ads.com
google-ads-sync.com
invitation-anthropic.com
leaks-entry.com
leaksentry-security.com
link-mcc.com
manus-meta.im
manusbymeta.com
manusmeta.im
mcc-account-sync.com
mcc-invitation.com
mcc-safety.com
mcc-security.com
mcc-verification.com
metamanus.im
monday-brief-claude.com
museads.ai
openai-ads.ai
openai-advertisers.com
openaiadsteam.com
perplexity-advertising.com
perplexity-beta-ads.com
perplexity-beta.com
safety-mcc.com
security-ads.com
security-mcc.com
semrush-ai.com
semrushads-ai.com
sponsored-gemini.com
sync-account-invite.com
sync-account.com
sync-ads-account.com
sync-ads.com
sync-business.com
sync-mcc-account.com
sync-mcc-data.com
sync-mcc-team.com
sync-tiktok.com
verification-security.com
adsclaudeback-production.up.railway.app
anthropicadsback.onrender.com
backend-j02u.onrender.com
backend-production-6d75.up.railway.app
backend-tg0j.onrender.com
chatgptadsback-production.up.railway.app
chatgptadsback.onrender.com
claudeadsback-production-67c1.up.railway.app
claudeadsback-production.up.railway.app
geminiback-5j1n.onrender.com
geminiback-production.up.railway.app
just-cooperation-production-f159.up.railway.app
manus2back-production.up.railway.app
manusback-bahk.onrender.com
manusback-production.up.railway.app
manusback.onrender.com
mbackend-mdye.onrender.com
museadsback-production.up.railway.app
semrushback.onrender.com
syncgadsback.onrender.com
syncgoogleadsback-production-6100.up.railway.app
syncgoogleadsback-production-cde6.up.railway.app
syncgoogleadsback-production.up.railway.app
syncgoogleadsback.onrender.com
tbackend-production-39ca.up.railway.app
[Refund]
confirm-payments.com
payment-confirm.com
payment-confirmation.com
payment-confirmations.com
payment-sync.com
payments-sync.com
refund-advertisers.com
sync-billing.com
sync-payment.com
sync-payments.com
backend-production-6d75.up.railway.app
[Recruit]
adeccohr-calendly.com
adeccohr-jobs.com
apple-career.com
nikehr-jobs.com
talent-louisvuitton.com
backend-production-6d75.up.railway.app
nikear.onrender.com
zero39172-391920.onrender.com
careers-interview.com
ferrar.careers-interview.com
ferrari-invite.com
redbullapply.careers-appointment.com
tesla-careerapplication.com
mango-back.onrender.com