Fake ChatGPT, Gemini sites steal ad accounts and MFA codes
A phishing campaign uses fake ChatGPT, Gemini, Claude, and Perplexity sites to steal login credentials and MFA codes via browser-in-browser attacks. It targets agency staff and media buyers with access to multiple client accounts, with a human operator manually requesting passwords and codes up to three times.
- Fake pages mimic ChatGPT, Gemini, Claude, and Perplexity
- Browser-in-browser attack spoofs an accounts.google.com window
- Operator manually requests password and MFA up to three times
- Kit adapts to Windows, macOS, iOS, and Android, including dark mode
Read next
Security