Fake AI Chatbot Sites Harvest MFA Codes via Browser-in-Browser Phishing
Attackers are exploiting the widespread trust and popularity of AI tools like ChatGPT and Gemini to lure advertising account managers into convincing phishing sites. Using Browser-in-Browser (BitB) attacks, the campaign renders realistic fake browser windows that mimic legitimate login portals, tricking victims into surrendering not just passwords but live MFA codes to human operators in real time. This matters because even security-conscious users with MFA enabled can be compromised when the attack intercepts tokens dynamically, bypassing a control many organizations consider a strong safeguard. The targeting of high-value advertising accounts on Google, Meta, and TikTok amplifies the financial and reputational damage potential.
Tactical Insight
Immediate actions
- Train employees to verify URLs at the OS/browser address bar level and never enter credentials into popups or embedded browser windows that lack a real address bar.
- Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys or passkeys) instead of SMS or TOTP codes, which can be intercepted in real time.
Long-term improvements
- Deploy browser isolation or enterprise browser solutions that detect and block BitB rendering techniques before users interact with malicious pages.
- Implement conditional access policies that restrict advertising platform logins to managed, compliant devices and known IP ranges.
- Establish a verified allowlist of legitimate AI tool domains and block lookalike or newly registered domains at the DNS/proxy layer.
Detection measures
- Monitor for anomalous login events on advertising platforms (unusual geolocations, rapid MFA prompts) and trigger automated account lockout workflows.
- Ingest threat intelligence feeds covering newly registered phishing domains mimicking popular AI brands and block them proactively.