Phishing Operation Targets Ad Managers with Fake Meta Muse and AI Portals
Security researchers at Island trace browser-in-browser credential theft targeting media buyers across Next.js frontends mimicking Meta, OpenAI, and Google.

Cybercriminals are exploiting the rollout of generative artificial intelligence tools by deploying browser-in-the-browser phishing campaigns aimed at corporate advertising teams, according to research from cybersecurity firm Island first reported by The Register (https://www.theregister.com/research/2026/10/07/browser-in-browser-attacks-use-fake-meta-muse-ad-lure-to-steal-credentials/5301505). Just days after Meta introduced its personal AI agent, Muse, on September 8, attackers launched a counterfeit website—museads.ai—pitching automated tools for ad placements.
The site purported to offer a product called Muse Ads to help advertisers reach buyers. However, Island researchers Oleg Zaytsev and Ofek Ronen found that the underlying infrastructure was already in active use. The attackers adapted an existing phishing platform previously configured with fake advertising portals for OpenAI's ChatGPT, Google's Gemini, Anthropic's Claude, Perplexity, and Manus.
The campaign uses a technique known as browser-in-the-browser (BitB), first documented by security researcher mr.d0x in 2022. BitB attacks generate a simulated browser window within the active webpage, rendering an address bar that displays legitimate domains such as accounts.google.com or an Okta single sign-on tenant. Because the visual window is an overlay, the victim remains on the phishing site while typing credentials into the fake prompt.
Zaytsev, Island's lead security researcher, told The Register that the campaign specifically targets media buyers, agency staff, and administrator accounts managing advertising spend. Compromising these credentials can lead to unauthorized advertising charges, account lockouts, and exposure of linked client portfolios. Because the operators already maintained the underlying software, retheming the platform for a newly announced brand took only minutes.
The operation relies on real-time human supervision. When a target enters credentials, an operator monitors the submission and dynamically selects the next prompt displayed to the victim. Depending on the targeted enterprise workflow, operators can request supplementary passwords, prompt for SMS or Okta authenticator multi-factor codes, trigger Google approval codes or Okta push requests, or display QR codes.
The underlying kit supports authentication workflows for Google, Meta, TikTok, and Okta. The interface adapts dynamically to the victim's platform across Windows, macOS, iOS, and Android, replicating browser-specific elements such as Safari's URL pill, Chrome custom tabs, and dark mode. Technical analysis shows the pages run on Next.js and Socket.IO, with frontends hosted on Vercel backed by Railway or Render cloud instances for state and command delivery.
Island researchers observed roughly 200 distinct email address submissions on a single frontend over approximately one month, with activity ongoing across multiple domains. Source code uncovered in misconfigured public GitHub repositories linked the AI campaign to earlier phishing operations that used fake job recruitment and refund portals impersonating Adidas, Google Careers, Robert Half, Tesla, and Louis Vuitton.
Zaytsev advised security teams to maintain strict baselines of trusted domains and inspect the primary browser address bar rather than embedded pop-up interfaces, noting that while attackers can quickly launch convincing frontends, replicating legitimate domain history and reputation remains significantly harder.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



