GajIPS - IPS Signature Update — GS PHISHING: Fake AI Ads Browser-in-the-Browser campaign
Severity: HIGH · Priority: P2 — live-operator MFA relay targeting advertising accounts, investigate on hit
These rules provide comprehensive detection for a sophisticated phishing-as-a-service campaign documented by Island.io on October 6, 2026, in which attackers place sponsored Google Ads for fake versions of prominent AI tools — ChatGPT, Gemini, Claude, Anthropic, Perplexity, Manus, and a newly minted fake "Muse Ads" created eight days after Meta launched Muse — and use them to steal advertising account credentials and multi-factor authentication codes from digital marketing professionals.
The attack is technically distinctive because it uses a Browser-in-the-Browser technique rather than a redirect to a lookalike site. When a victim clicks the "Connect" button on what appears to be a legitimate AI advertising tool, a fake Google sign-in window appears embedded inside the original page, complete with a spoofed accounts.google.com address bar. The window is an iframe styled to look like a pop-up, not a real browser window. A human operator monitors victim sessions in real time and sends commands to the victim's browser through a persistent Socket.IO channel — selecting which authentication challenge to show next: a password prompt (up to three times), an SMS code entry, a Google authenticator prompt, a QR code verification, an Okta push notification, or an Okta authenticator app request. The attack intercepts the credentials and MFA codes as they are entered and uses them in real time to authenticate to the real platform before the session expires. Google advertising accounts, Meta Business Manager, TikTok Ads Manager, and Okta-gated enterprise SSO are all targeted by this kit.
A hit on any behavioral rule or a lure-domain rule indicates a user on your network is actively engaged with the phishing kit and may already be in the MFA relay step. Act immediately: a human operator on the attacker's side is watching and directing the session in real time, and the window between credential entry and account takeover can be seconds. Identify the affected user, immediately revoke all active sessions for any accounts they may have entered credentials for — prioritise Google Ads, Meta Business Manager, TikTok Ads, and Okta — and audit all active OAuth authorisations and recent ad campaign changes. Because the kit specifically targets advertising accounts, also audit for fraudulent ad spend, modified payment methods, and newly created ad campaigns from the compromised accounts.