Advertising account administrators are the focus of a fresh phishing campaign that impersonates well-known AI chatbot services, harvesting not just passwords but the one-time passcodes entered to verify them, according to a report covered by BleepingComputer.

The counterfeit sites spoof at least four platforms — ChatGPT, Gemini, Claude and Perplexity — and are engineered to capture login credentials and multi-factor authentication (MFA) codes as they are typed. The report does not name the threat actor behind the operation. What it does establish is who is being targeted: the staff who control billing relationships, saved payment methods, campaign budgets and customer lists for businesses.

The deception is not the logo — it is the browser window itself

Fake brand login pages are a staple of phishing. What distinguishes this campaign, as the BleepingComputer report lays out, is the delivery method: browser-in-the-browser (BiB) attacks.

Instead of hosting a login form in a tab that is visibly wrong, the attackers deploy JavaScript that renders a replica of the browser's own chrome — address bar, tab strip, padlock icon — inside a malicious page. The victim sees what looks like a legitimate chatbot sign-in window, prompted to log in to continue using an AI tool their organisation has recently adopted.

That neutralises the single habit security awareness training relies on most: checking the address bar before entering credentials. The victim performs the check. They simply see an address bar drawn by the attacker's page rather than by the browser.

MFA intercepted in real time

Layered on top of the UI spoofing is live interception of the second factor. Because the fake sign-in window sits directly in the user's session, it captures the one-time passcode at the moment it is entered, then relays the password and code together to a genuine login attempt.

In effect, the attacker relays the user's credentials in real time — a separate mechanism from the visual spoofing, and one that defeats both push-based MFA and SMS one-time passcodes, the two options most small and mid-sized businesses deploy. Only phishing-resistant methods — passkeys and FIDO2/WebAuthn hardware security keys — withstand this class of attack, because the credential is cryptographically bound to the domain the browser actually presents, not to whatever page the user is looking at.

Why ad accounts

The target selection appears deliberate. A compromised advertising account is far more than a login: it typically bundles payment instruments, saved card details, audience data and the authority to redirect spend. For an organisation without dedicated security staff, one stolen credential set can set off a chain of harm — ad budgets diverted to attackers, customer lists exfiltrated, and lateral movement into wider systems if the same password is reused.

The lure also exploits a trend the campaign rides on. As AI chatbots have become part of ordinary work, staff are prompted to sign in to unfamiliar services regularly. Unpredictable login requests now read as normal, eroding exactly the scepticism phishing depends on.

Practical steps

The defensive response does not require new tooling — only a few defaults changed:

  • Type the URL yourself. Treat unexpected sign-in prompts — especially ones rendered inside another page rather than as a full browser tab — as suspect. Enter the service address manually or use a bookmark.
  • Move high-value accounts to hardware keys or passkeys. For anything handling payments, customer data or ad spend, a FIDO2 security key or passkey is the only MFA that reliably resists real-time interception.
  • Use unique, manager-stored credentials per service. Password reuse means one chatbot compromise propagates everywhere instantly.
  • Audit ad accounts for unexpected administrators, payment changes and new redirect rules.
  • Report it. Forward suspected phishing pages to your organisation's security team, and where relevant, to the anti-fraud or law-enforcement authority in your jurisdiction.

Attackers are no longer only stealing passwords. They are stealing the verification step — inside a window that no longer tells you who drew it.


據 BleepingComputer 報道,一項針對廣告帳戶管理員的新一輪釣魚攻擊正在進行,攻擊者冒充知名 AI 聊天機器人服務,不僅竊取密碼,更擷取用戶輸入用以驗證密碼的一次性通行碼。

仿冒網站至少偽造了四個平台——ChatGPT、Gemini、Claude 及 Perplexity——並經過特別設計,能在用戶輸入時即時擷取登入憑證及多因素認證(MFA)碼。報告並未指出操縱這次行動的威脅行為者身份,但明確指出了攻擊目標:負責企業帳單關係、儲存付款方式、廣告活動預算及客戶名單的員工。

騙局關鍵不在 logo——而是瀏覽器視窗本身

偽冒品牌登入頁面一直是釣魚攻擊的慣用伎倆。根據 BleepingComputer 報告所指出,這次行動的獨特之處在於其投遞方式:browser-in-the-browser(BiB)攻擊。

攻擊者並非將登入表格放在一個明顯錯誤的分頁中,而是在惡意頁面內部署 JavaScript,繪製出與瀏覽器自身介面框架無異的仿製版本——網址列、分頁列、鎖頭圖示一應俱全。受害者看到的是一個貌似合法的聊天機器人登入視窗,並被要求登入以繼續使用其所在機構最近採用的 AI 工具。

這使安全意識培訓最依賴的一項習慣徹底失效:在輸入憑證前檢查網址列。受害者的確做了檢查——他們看到的只是由攻擊者頁面繪製的網址列,而非瀏覽器本身顯示的網址列。

MFA 在即時傳輸中被攔截

在介面偽造之上,第二重認證因子亦被即時攔截。由於假冒登入視窗直接運行於用戶的 session 之內,它會在用戶輸入一次性通行碼的瞬間將其擷取,隨後把密碼與驗證碼一併轉送至真正的登入程序。

換言之,攻擊者以即時方式轉發用戶的登入憑證——這與視覺偽造屬另一套機制,卻足以同時繞過以推送方式運作的 MFA 及 SMS 一次性通行碼,而後者正是大多數中小企業所採用的兩種方式。只有具抗釣魚能力的認證方法——passkeys 及 FIDO2/WebAuthn 硬件安全金鑰——能夠抵禦這類攻擊,因為相關憑證是以密碼學方式與瀏覽器實際呈現的 domain 綁定,而非與用戶正在瀏覽的頁面綁定。

為何以廣告帳戶為目標

目標選擇看似刻意而為。一個被入侵的廣告帳戶所代表的遠不只是一組登入資料:它通常捆綁了付款工具、儲存的信用卡資料、受眾數據,以及轉移廣告支出的權限。對於沒有專職網絡安全人員的機構而言,一組被竊的憑證便足以引發連串損害——廣告預算被轉移至攻擊者、客戶名單外泄,若同一密碼被重用,攻擊者更可橫向移動入侵更廣泛的系統。

誘餌亦依附並利用了一項趨勢。隨著 AI 聊天機器人成為日常工作的一部分,員工會定期被要求登入陌生服務。如今不尋常的登入要求已變得見怪不怪,正好削弱了釣魚攻擊所依賴的警覺心。

實際應對步驟

這項防禦應對並不需要引入新工具——只需更改少數預設設定:

  • 自行輸入網址。 將非預期的登入提示——尤其是那些嵌入在另一網頁之內、而非以完整瀏覽器分頁形式呈現者——視為可疑。請手動輸入服務網址或使用書籤。
  • 將高價值帳戶改用硬件金鑰或 passkey。 對於任何涉及付款、客戶數據或廣告支出的帳戶,FIDO2 安全金鑰或 passkey 是唯一能可靠抵禦即時攔截的 MFA 方式。
  • 每個服務使用獨一無二、由密碼管理器儲存的憑證。 密碼重用意味著一個聊天機器人被入侵,即時波及所有帳戶。
  • 審核廣告帳戶的異常管理員、付款變更及新增轉向規則。
  • 主動舉報。 將懷疑的釣魚頁面轉交予所屬機構的網絡安全團隊,如有需要,亦可向你所在司法管轄區的反詐騙機構或執法部門舉報。

攻擊者已不再只是竊取密碼——他們竊取的是驗證這一步驟,而負責攔截的視窗,再也不會告訴你,究竟是誰將它畫出來的。

新聞來源 / Original News Source