One “Connect” button sits at the center of every lure in a phishing platform that Island’s researchers took apart in a report dated October 6, 2026. Clicking it opens what looks like a Google sign-in window, complete with accounts.google.com in its address bar, but the window is only a picture drawn inside the web page. Behind it, a human operator watches the victim’s passwords arrive and decides which verification prompt to show next. Island says it saw hundreds of victim submissions to the platform.
The lures are dressed as artificial-intelligence tools for people who buy advertising. Fake ChatGPT, Gemini, Claude, Perplexity and Manus pages each carry a pitch tailored to ad work, and the newest imitated Muse Ads, a page that surfaced about eight days after Meta introduced its Muse personal agent on September 8, 2026.
A sign-in window that never leaves the page
Island’s analysis, “Behind the Connect Button,” credits its authors, Oleg Zaytsev and Ofek Ronen, with documenting a technique known as browser-in-the-browser. The researcher known as mr.d0x described the method in March 2022 as a way to simulate “a browser window within the browser to spoof a legitimate domain,” built from ordinary HTML and CSS with an iframe pointing at the attacker’s server. In this campaign the fake window shows a trusted address while the real browser tab stays on the phishing domain. Because it is an iframe, it cannot be dragged outside the browser or resized the way a genuine OAuth pop-up can.
The operator side is what separates the platform from a static phishing kit. Island found that the person behind the console can reject a submitted password and ask for another, with retry logic that allows up to three password attempts, then pick the next challenge: an SMS code, an authenticator-app code, an Okta push request, a Google approval prompt or a QR code. The kit restyles itself for Windows, macOS, iOS and Android, including dark mode, and supports Google, Meta, TikTok and Okta sign-in flows.
It also rebuilds each provider’s interface locally rather than proxying the real one. Island says that makes the network traffic look like an AI product talking to an unrelated backend, which blunts the detections that watch for a known login page being relayed.
Codes that arrive in the attacker’s hands
A one-time code protects an account only when it goes to the real service. CISA’s fact sheet on implementing phishing-resistant MFA labels SMS and voice codes as “vulnerable to phishing, SS7, and SIM swap attacks,” explaining that a fake site can collect the password and the six-digit code together and use the code on the real site before it expires. App-generated codes fail the same way, the agency says, and it calls FIDO/WebAuthn “the only widely available phishing-resistant authentication.”
Island lands on the same remedy. Its report says “origin-bound passkeys and hardware-backed authentication remove the reusable password,” and advises checking the real browser’s origin because on-page address bars, lock icons and dialogs can all be faked. It also recommends reaching AI beta programs, ad products and account connectors through the vendor’s official site rather than through an invitation link.
Manager accounts and the clients behind them
Ad accounts are the prize because of how agencies organize them. Google’s help center describes a manager account as an umbrella account linking several client accounts so they can be run from one place. Island says a visitor who signs in on one of the fake pages “handed that account, and every ad account behind it, to a human operator watching in real time,” and that a manager account can reach several client accounts, each with its own billing profile and linked users.
That reach explains the audience: agency staff, media buyers and administrators. BleepingComputer’s write-up notes that attackers can spend the balances on fraudulent campaigns or resell the access. Island’s wording on scale is “hundreds of victim submissions,” and BleepingComputer points out that this does not necessarily mean hundreds of compromised accounts.
The same machinery served other bait. Island tied one backend to 73 archived scans across 25 page domains between May 27 and June 20, linking the AI ad lures to refund-confirmation pages and a fake job site. Recruitment pages imitated Tesla, Louis Vuitton, Nike and Adecco, and older source code sat in misconfigured public GitHub repositories, including one named recruiterid/teslanewnewne, where the same routes and Telegram control channel appeared.
Hosting was deliberately ordinary. Front-end pages often ran on Vercel, with state and command servers on Railway or Render, and the operator console pushed instructions over Socket.IO while the victim was still looking at the page. Island argues that defenders should hunt for those client patterns and the platform’s control vocabulary, which it calls more distinctive than shared hosting addresses. After any exposure, the report says, the identity involved should be reviewed across every client account it could reach for unauthorized managers, changed recovery details and unapproved spending.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The NSA says three phone features should be off whenever you aren’t using them
- Hurricane Hunter radar shows four warning signs that a tropical cyclone is about to strengthen, a University of Miami study found
- Tropical Storm Rachel is dumping up to 12 inches on four Mexican states on its way to major hurricane strength
- The FTC says Lens.com doubled the price shoppers saw in Google ads