A new campaign reported by BleepingComputer uses fake versions of popular AI chatbots to steal advertising account credentials. The fake sites impersonate ChatGPT, Gemini, Claude, and Perplexity, and are aimed squarely at people who manage advertising accounts.
The attack relies on a browser-in-browser technique, where a convincing pop-up window appears inside the real browser session. That fake window is designed to harvest login credentials and multi-factor authentication (MFA) codes as the victim enters them, giving attackers a way around standard account protections.
The source report does not specify which ad platforms are targeted or how the fake sites are distributed. It notes only that the campaign is currently active and that ad account managers are the intended victims, making the attack a notable reminder that AI tools are now a common lure in credential phishing.