20
 min read
October 6, 2026
|
Updated: 

Behind the Connect Button: The Fake AI Ads Campaign

Security Research

Eight days after Meta launched Muse, operators added a fake Muse Ads product to a human-operated phishing platform already impersonating Gemini, Claude, ChatGPT, and Perplexity.

TLDR

Island security research uncovered a human-operated phishing platform disguised as a portfolio of AI advertising products. Its products ranged from campaign optimization and spend audits to business-account connections. The newest lure, Muse Ads, appeared shortly after Meta announced Muse.

Each product was built around the same action: Connect. Clicking it opened a browser drawn inside the real browser. The fake address bar displayed trusted origins such as accounts.google.com or an Okta tenant, while the real browser remained on the phishing domain. Behind the interface, the platform kept every password attempt, fingerprinted the device, and let an operator pick which MFA challenge the victim saw next.

The operators exposed source code for earlier versions of the platform through misconfigured public GitHub repositories, which reveals the operating model behind the pages. While tracking the campaign, we saw hundreds of victim submissions to the platform, and activity was still ongoing at the time of writing. Human operators could hold a victim on a waiting screen, reject a password, choose the next MFA prompt, and redirect the victim when the flow was complete. The same machinery is reused for refund and recruitment lures. 

Muse Ads was the platform's newest skin

Meta introduced Muse as a personal AI agent on September 8, 2026. Meta's announcement described an agent that could work across the apps people use every day.

By September 16, “museads.ai” was presenting a new product: Muse Ads, described as “Your AI ads manager for paid media workflows.” It promised to help advertisers reach buyers, connect an advertising account, and run sponsored placements.

Figure 1: Spoofed Muse Ads page, September 19.

The danger sat behind the Connect button. A visitor who clicked it and signed in with Google handed that account, and every ad account behind it, to a human operator watching in real time. Only the page was new. Its code, from the sign-in forms to the fake browser window, came from a wider operation that had already run fake ad products for Gemini, Claude, ChatGPT, Perplexity, and Manus.

The lure is a product, not a password prompt

Every brand gets its own pitch. ChatGPT promises a Monday Google Ads brief. Gemini promises MCC (manager account) and linked-client support. Claude gets its own advertising portal, Perplexity offers campaign planning and spend audits, and Manus offers a private Meta integration.

Figure 2: Spoofed ChatGPT Monday Brief page promising a weekly Google Ads briefing.

The copy is written in advertiser shorthand like MCC and ROAS, so a request to connect an account feels routine. Every page leads to the same action: Connect. Invitation emails that send victims to these pages have been documented by IRONSCALES and Intezer.

The Connect button opens a browser that is not a browser

Clicking Connect does not open Google. The page draws a fake Google window inside itself.

An after-Connect capture shows the real browser still sitting on the phishing domain. Inside it, the page renders a second Chrome window, complete with a lock icon and an address bar reading accounts.google.com.

Figure 3: Clicking Connect on the spoofed Gemini Ads page opens a fake Google sign-in window.

This technique is known as Browser-in-the-Browser.

The fake browser adapts to whatever the visitor runs, from Windows and macOS to iOS and Android. Newer builds copy the small details as well, like Safari’s URL pill, Chrome’s custom tabs, and a dark mode.

The bundle even contains comments explaining why the fake chrome needs a frosted treatment:

/* Real iOS Safari and Chrome custom tabs use frosted toolbars.
   Without this, the chrome looks painted-on and gives away the fake. */

.iab-chrome-translucent {
  backdrop-filter: saturate(180%) blur(20px);
}

The fake browser is a remotely controlled state machine

The fake Google window is only the presentation layer. Underneath it is a state machine designed to follow the victim through authentication. A human operator, the attacker running the campaign, can see each submission and decide what the victim sees next.

When the visitor clicks Connect, the client creates a record through /api/create/user. It then fingerprints the device, from IP and location down to screen size and WebGL, and sends the profile to /api/send/ip.

The state object can retain identity details and three separate password attempts:

password_one
password_two
password_three

This is deliberate retry handling. An operator can reject one entry, ask the victim to try again, and preserve every submitted value.

Figure 4: Victim data and operator commands move over Socket.IO while the attacker attempts the login in real time.

The platform supports Google, Meta, TikTok, and Okta workflows. Its command vocabulary includes:

/password           request another password
/2fa                request an SMS code
/authApp            request an authenticator code
/googlePrompt       show a Google approval prompt
/googleQrVerify     display a supplied QR payload
/verifyTap          display a supplied tap number
/oktaApprove        show an Okta push request
/oktaAuthApp        request an Okta authenticator code
/wrong2fa           reject the current code
/done               complete the flow
/ban                suppress the page for the visitor

Commands arrive through Socket.IO events such as operator-command and telegram-command. The backend chooses the next screen while the victim is still engaged.

Unlike a transparent reverse-proxy kit, the visible platform locally rebuilds the provider interface and collects credentials and MFA state through its own APIs. That makes the traffic look like an AI product talking to an unrelated application backend, rather than a browser session passing through a classic identity-provider proxy.

One phishing platform, many brands and business workflows

Under every brand, the application stayed the same. AI ad pages, refund claims, and fake job sites all run on one Next.js and Socket.IO stack. They call the same endpoints and hand the victim to the same operator commands.

Figure 5: Spoofed frontends across three lanes: Claude, Muse, Perplexity, Gemini; escrow hold, refund, billing, payment confirmation; Tesla, Louis Vuitton, Nike, and Adecco calendar.

The product story changed faster than the underlying flow. Infrastructure was modular: many observed branches used Vercel-hosted pages with Railway or Render services behind them for state and commands.

One backend makes the link concrete. backend-production-6d75.up.railway.app appeared in 73 archived scans across 25 page domains between May 27 and June 20. Its clients ranged from Gemini, OpenAI, and Anthropic ad lures to refund pages and a fake Louis Vuitton careers site. A page selling an AI ads product and a page offering a fake job talked to the same server. It is the clearest link between the lanes.

The retained sequence shows the platform moving through several AI brands during 2026. These are the earliest observations we retained, not the first day each site operated.

Figure 6: Earliest sighting of each AI brand in 2026.

The operators exposed older source code through misconfigured public GitHub repositories, which makes the recruitment reuse visible. The recruiterid/teslanewnewne frontend and recruiterid/newnewtesla backend show the same routes and the same three-password retry model, with Telegram wired in as the control channel. A second disposable account, `reudisace`, published related recruitment builds for Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton. The newer AI advertising bundles preserve the same unusual state language and extend the control model with tenant-aware routing and expanded Google and Okta states.

Figure 7: Spoofed Tesla recruitment page, July 2025.

Why advertising operators are valuable targets

The lures are written for agency staff, media buyers, and manager-account administrators, because an advertising account is a spending account. It carries a stored payment method and an approved budget, and a manager account can reach several client accounts, each with its own billing profile and linked users.

Figure 8: AI-branded phishing lures target advertising manager accounts, where one compromised identity can expose multiple client accounts and enable fraudulent spending or account resale.

Mimecast’s ad account theft research describes two ways attackers monetize a stolen account: spend its budget on their own campaigns, often a short-lived gain, or sell it. Aged accounts with a clean spend history sell on Telegram for 2 to 4 times the price of new ones, complete with escrow and warranties. Google Ads accounts for high-risk verticals list at roughly $200 to $270.

For the victim, the card is the easy part: they can remove it within hours. Getting the account back is not. Attackers typically add their own administrators and downgrade the legitimate owner, and recovery can take weeks or months while the account keeps serving ads. For a manager account, the damage reaches the agency’s clients.

The recruitment lane targets a different victim. Someone applying for a job is usually employed somewhere else and may sign in with a work Google or Okta identity, so one stolen login can open their current employer’s email, files, and SaaS apps.

What security teams should do next

Phishing pages are now built to order. Each one in this campaign poses as a believable product, with its own brand, pitch, and sign-in flow. They also move with the news. Muse Ads appeared within eight days of Meta announcing Muse, so a brand-new product launch is exactly when a fake one looks most convincing. AI makes that pace possible, and turning a phishing idea into a polished, branded page now takes minutes.

  • Treat fictional AI integrations as account-access requests. Verify beta programs, advertising products, and account connectors through the vendor's official site.
  • Inspect the outermost origin. A page can draw an address bar, lock icon, browser tab, QR prompt, or security dialog. It cannot change the real browser origin.
  • Correlate the client pattern. Strong combinations include google_uid, repeated password fields, api.ipify.org, ipapi.co, /api/send/ip, /api/create/user, and Socket.IO connections to unrelated Railway or Render hosts.
  • Hunt for the control vocabulary. add-user, update-user, operator-command, telegram-command, Google and Okta state names, and the exact password-retry language are more useful than commodity hosting IPs.
  • Use phishing-resistant authentication. Origin-bound passkeys and hardware-backed authentication remove the reusable password and one-time-code material this platform is built to collect.
  • Review advertising control changes. After exposure, check every client account the identity could reach for new managers or partners, changed recovery details, and campaigns or spend nobody approved.

The browser is where the invitation, product, identity flow, and business application meet. Island is built to give organizations visibility and control across that entire path.

IOCs

[Ads]
account-sync-data.com
ads-claude-beta.com
ads-claude.com
ads-team-openai.com
adsmistral.com
advertising-chatgpt.com
advertising-gemini.com
ai-ads-platform.com
ai-brand-safety.com
anthropic-ads-beta.com
anthropic-ads-marketing.com
anthropic-ads.com
anthropic-beta-ads.com
anthropic-crm-1.com
anthropic-sponsored.com
beta-anthropic.com
beta-chatgpt.com
beta-gemini-ads.com
beta-manus.com
beta-perplexity.com
business-gemini.com
chatgpt-advertise.com
chatgpt-advertisement.com
chatgpt-beta.com
chatgpt-brief.com
chatgpt-briefing.com
chatgpt-monday-brief.com
claude-ads-beta.com
claude-ads-invitations.com
claude-ads-portal.com
claude-ads.ai
claude-advertisement.com
claude-advertisers.ai
claude-advertisers.com
claude-beta-invite.com
claude-beta.com
cursor-ads.com
escrow-ads.com
gemimi-ads.com
gemini-ads-ai.com
gemini-ads-invite.com
gemini-ads-team.com
gemini-ads.ai
gemini-advertisers.com
gemini-beta-invitations.com
gemini-beta-invites.com
gemini-business.com
gemini-google-ads.com
gemini-invitation.com
gemini-invitations.com
gennini-ads.com
google-ads-sync.com
invitation-anthropic.com
leaks-entry.com
leaksentry-security.com
link-mcc.com
manus-meta.im
manusbymeta.com
manusmeta.im
mcc-account-sync.com
mcc-invitation.com
mcc-safety.com
mcc-security.com
mcc-verification.com
metamanus.im
monday-brief-claude.com
museads.ai
openai-ads.ai
openai-advertisers.com
openaiadsteam.com
perplexity-advertising.com
perplexity-beta-ads.com
perplexity-beta.com
safety-mcc.com
security-ads.com
security-mcc.com
semrush-ai.com
semrushads-ai.com
sponsored-gemini.com
sync-account-invite.com
sync-account.com
sync-ads-account.com
sync-ads.com
sync-business.com
sync-mcc-account.com
sync-mcc-data.com
sync-mcc-team.com
sync-tiktok.com
verification-security.com
adsclaudeback-production.up.railway.app
anthropicadsback.onrender.com
backend-j02u.onrender.com
backend-production-6d75.up.railway.app
backend-tg0j.onrender.com
chatgptadsback-production.up.railway.app
chatgptadsback.onrender.com
claudeadsback-production-67c1.up.railway.app
claudeadsback-production.up.railway.app
geminiback-5j1n.onrender.com
geminiback-production.up.railway.app
just-cooperation-production-f159.up.railway.app
manus2back-production.up.railway.app
manusback-bahk.onrender.com
manusback-production.up.railway.app
manusback.onrender.com
mbackend-mdye.onrender.com
museadsback-production.up.railway.app
semrushback.onrender.com
syncgadsback.onrender.com
syncgoogleadsback-production-6100.up.railway.app
syncgoogleadsback-production-cde6.up.railway.app
syncgoogleadsback-production.up.railway.app
syncgoogleadsback.onrender.com
tbackend-production-39ca.up.railway.app

[Refund]
confirm-payments.com
payment-confirm.com
payment-confirmation.com
payment-confirmations.com
payment-sync.com
payments-sync.com
refund-advertisers.com
sync-billing.com
sync-payment.com
sync-payments.com
backend-production-6d75.up.railway.app

[Recruit]
adeccohr-calendly.com
adeccohr-jobs.com
apple-career.com
nikehr-jobs.com
talent-louisvuitton.com
backend-production-6d75.up.railway.app
nikear.onrender.com
zero39172-391920.onrender.com
careers-interview.com
ferrar.careers-interview.com
ferrari-invite.com
redbullapply.careers-appointment.com
tesla-careerapplication.com
mango-back.onrender.com

‍

Oleg Zaytsev

Oleg is a Lead Security Researcher at Island, helping make Island the most secure and resilient enterprise browser. With a background in cybersecurity from Unit 8200 and leading security companies, Oleg drives security research, threat hunting, and vulnerability discovery. His work uncovering critical vulnerabilities and threat campaigns has helped shape Island’s security practices and strengthened its security standards.

Ofek Ronen

Ofek is a Security Researcher at Island, where he combines a machine learning background with hands-on threat research to detect and disrupt emerging attacks. A graduate of Ben-Gurion University of the Negev with a degree in Information Systems Engineering, Ofek spent five years at Perception Point and Fortinet building ML-driven detection systems that surfaced hundreds of thousands of real-world threats daily. His work spans machine learning, email and identity security, threat detection, and phishing campaign analysis. At Island, Ofek applies this expertise to anticipate attacker behavior and strengthen browser security, helping raise the bar for how enterprises stay protected.