On October 6, 2026, researchers from Island published an analysis of a phishing platform that targets not random users, but those who manage other people's advertising budgets: agency employees, media buyers, and account administrators. The bait is "AI advertising tools" under the brands ChatGPT, Gemini, Claude, Perplexity, Manus, and the new Meta Muse. The "Connect" button opens a fake Google or Okta login window, while a live operator collects the password and two-factor code in real time. Let's break down how the scheme works, why anti-detect tools and proxies won't help, and what the team can change in their operations today.
What Exactly Was Found at Island
Island researchers Oleg Zaitsev and Ofek Ronen described the platform as a "portfolio of AI products for advertising": the sites promise campaign optimization, expense audits, and business account connections. In reality, they all have one goal — to obtain the login, password, and one-time code.
- Scale. Island documented over 73 fraudulent domains. During three months of observation, which ended in August 2026, the related delivery cluster included about 850 landing pages from paid advertising, 26 ChatGPT impostors, and 71 Google Ads campaign identifiers.
- Speed of response to news. Meta announced the AI advertising assistant Muse on September 8, 2026. Eight days later, on September 16, a fake museads.ai appeared promising to "connect advertising accounts."
- Targets. Google Ads, Meta, TikTok, and corporate logins via Okta.
- Scale of victims. According to BleepingComputer, the managing Telegram channel received hundreds of data submissions from victims, and the infrastructure can be traced back at least to March 2026.
The same engine runs other scenarios: fake job postings in the names of Tesla, Louis Vuitton, Nike, Adecco, and "payment refunds." Some source code was found in open GitHub repositories that the operators forgot to close.
How the Attack Works: the Connect Button and the Window Drawn Inside the Page
The key trick is browser-in-the-browser (BitB). The victim clicks "Connect," and a "popup" Google login window appears over the page with the correct title, interface, and expected address in the address bar. As noted by Island, this window is simply an iframe drawn inside the phishing page. The real browser remains on the fraudster's domain the entire time.
The creators paid attention to details. In the leaked code, there is a comment stating that real Safari on iOS and Chrome tabs use a matte panel, and without it, the fake frame "looks drawn" and reveals the forgery. This means they deliberately bypass visual checks "by eye."
Live Operator Instead of a Script
This is not a classic setup that simply saves the password. The frontend on Next.js is connected to the operator's panel via Socket.IO, and a person on the other side decides in real time which screen to show the victim:
- re-enter the password (the code allows for three attempts);
- enter the code from SMS or from an authenticator app;
- confirm a push request from Google or Okta on the phone;
- complete the scenario or block the "suspicious" visitor.
The operator can reject the entered code and request a new one — while simultaneously logging into the real account with the obtained data. Standard two-factor authentication with codes does not help against such real-time interception: the code is simply forwarded to the real login form while it is still valid.
The Victim's Fingerprint is Also Collected
The platform collects the visitor's IP, geolocation, screen size, and WebGL data. Island directly refers to this as fingerprinting. For an arbitrageur, these are familiar parameters: this is how platforms assess whether a new login "looks like" the usual one. The collected fingerprint helps the attackers filter out researchers and likely makes logging into the stolen account less suspicious.
What Happens to the Account After Capture
According to Island, attackers typically add their administrators to the account and downgrade the rights of the actual owner. There are two monetization paths:
- Draining the budget on their own campaigns, often fraudulent, using the linked card or credit line.
- Reselling the account. Accounts with a "clean spending history" are particularly valued: Island mentions a price of $200–270 for a Google Ads account.
The most concerning aspect is access through the manager account. By hacking the agency's MCC or the Business Manager administrator, the attacker gains leverage over many client accounts at once. This is why the target is chosen so precisely: one media buyer opens the door to dozens of budgets.
This is not an isolated story. In July 2026, Mimecast described the theft of advertising accounts as a "mass commodity crime" in the advertising ecosystem: stealers like VietCredCare, DuckTail, NodeStealer, and PXA Stealer have put account hijacking on stream. The new platform adds social engineering to the trendy theme of AI.
Why Anti-Detect and Proxies Don't Protect Here
Many teams believe that since each account lives in its own anti-detect browser profile with its own IP, it is safe. Not from this attack — and it's important to understand why.
- Profile isolation protects against account linking, not phishing. If you opened a fake site in the account profile and entered your password, no isolation will help: you voluntarily gave away your data.
- Proxies hide your address from the platform, but do not check where you enter it. The BitB window appears the same regardless of the IP.
- The two-factor code is one-time, but not tied to the site. The operator enters it into the real Google form within seconds.
However, good network hygiene helps to notice the hijacking. If an account has been logging in from a stable IP in one region for years, a login from another location stands out in the security log. More on why an account needs a permanent address can be found in the analysis on how long to keep an IP on an advertising account.
Checklist for Media Buyers and Agencies
1. Check the "login window" in five seconds
- Try to drag the login window outside the tab. A real browser popup moves freely, while an iframe does not go beyond the page boundaries.
- Look at the address in the real address bar of the browser, not in the "window." Island puts it this way: the page can draw an address bar and a lock, but cannot change the real origin of the browser.
- Pay attention to the password manager. If it does not offer autofill where it usually does, you are likely not on the correct domain. This is one of the most reliable signals.
2. Switch to access keys where possible
Island directly recommends phishing-resistant authentication: passkeys and hardware keys are tied to the domain, so they simply won't work on a fake site, and there is nothing for the operator to intercept. If you manage many accounts in anti-detect, access keys need to be set up carefully to avoid linking accounts together. How to do this is discussed in the article about passkeys and multi-accounting.
3. Treat "AI integrations" as access requests
- Any "connect account" button on a third-party site is a request to grant access to funds.
- Learn about beta programs and new tools from Meta, Google, and TikTok on the vendors' official sites, not from ads and emails.
- Be wary of professional jargon in invitation emails (MCC, ROAS): Island notes that the bait is deliberately written in the language of advertisers to make the email seem routine.
4. Separate roles and limit damage
- Do not use an account with MCC or Business Manager administrator rights for everyday work and testing new services.
- Grant the minimum necessary rights: analysts — read-only, buyers — campaign management without the right to change users.
- Set spending limits and separate payment methods for accounts to prevent hijacking from turning into a total budget drain.
5. Monitor changes in accounts
- Enable notifications for new users, changes in rights, and recovery data.
- Regularly check the change log: new administrators, unknown campaigns, changes to payment data.
- Keep a permanent IP and one profile for each account: this way, unauthorized access is noticeable immediately, not after a week in the statement.
What Proxies Are Needed for Advertising Accounts
Proxies do not protect against phishing, but they ensure that your own logins appear stable and do not trigger checks. For working with Google Ads, Meta, and TikTok, the following are typically chosen:
- residential proxies with sticky sessions and country binding to the account — the address of the home provider that does not change during work;
- mobile proxies — for mobile scenarios and accounts that were originally created on a phone.
The main rule is the same as in security: one account — one profile — one stable region. If you still need to change the address, do it step by step; otherwise, the platform will treat you as a hijacker. Typical mistakes are discussed in the article about moving an account to a new proxy.
Conclusion
The scheme described by Island shows a shift: they are not hunting accounts one by one, but rather targeting people with access to many accounts at once, using the trendiest bait of the season — "AI for advertising." The fake login window and live operator bypass both careful scrutiny and standard two-factor codes. Three things work: checking the real page address, using access keys instead of codes, and separating rights. Anti-detect and proxies remain tools for stable operations, not shields against one's own mistakes when logging in.
