Fake AI Chatbot Ads Steal Business Credentials and MFA Codes
A new phishing platform mimics ads for popular AI tools to harvest login credentials and bypass multi-factor authentication. Security teams should警惕此类社会工程攻击的增加。
TL;DR
- Attackers created fake ad portals mimicking ChatGPT, Gemini, and Claude marketing tools
- Platforms trick users into entering credentials and approving MFA prompts
- Targets include businesses using AI advertising products
- Human operators manage the phishing campaigns in real-time
- Security teams should train staff to verify ad portal authenticity
Cybercriminals have launched a sophisticated phishing operation that impersonates advertising platforms for leading AI chatbots including ChatGPT, Google Gemini, and Anthropic Claude. These fake portals are specifically designed to target businesses that advertise on AI platforms, tricking employees into surrendering their login credentials and approving malicious multi-factor authentication requests.
The attack represents a growing trend in human-operated social engineering campaigns that leverage the popularity and business adoption of AI tools. Unlike automated phishing attempts, these platforms use real operators who can adapt their approach based on victim responses, making them particularly dangerous for enterprise security teams.
How the Phishing Platforms Operate
- Fake portals mimic legitimate advertising dashboards for AI chatbot platforms
- Victims are prompted to log in with existing business account credentials
- Attackers intercept multi-factor authentication codes in real-time
- Human operators guide victims through the authentication process
- Stolen credentials provide access to actual business advertising accounts
Protecting Your Organization
- Verify the authenticity of AI platform advertising portals through official channels
- Implement strict policies for accessing third-party advertising dashboards
- Train staff to recognize sophisticated social engineering tactics
- Monitor for unauthorized access to business AI platform accounts
- Consider enhanced authentication methods beyond SMS-based MFA
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.