Full Report
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
Analysis Summary
# Tool/Technique: Browser-in-the-Browser (BitB) AI Phishing Campaign
## Overview
This technique involves a sophisticated phishing operation targeting advertising account managers (Meta, TikTok, Google) by impersonating popular AI platforms like ChatGPT, Gemini, Claude, and Perplexity. The attack utilizes a "Browser-in-the-Browser" (BitB) framework to create deceptive, functional login pop-ups within a malicious webpage to harvest credentials and bypass Multi-Factor Authentication (MFA) in real-time.
## Technical Details
- **Type:** Phishing Technique / Man-in-the-Middle (Adversary-in-the-Middle) Framework
- **Platform:** Windows, macOS, iOS, and Android (Adaptive UI)
- **Capabilities:** Credential harvesting, MFA bypass (SMS, Authenticator, Push, QR codes), Real-time operator interaction.
- **First Seen:** Technique originally documented March 2022; this specific campaign active since at least March 2024.
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- **T1566.002 - Phishing: Spearphishing Link**
- **TA0006 - Credential Access**
- **T1557 - Adversary-in-the-Middle**
- **T1539 - Steal Web Session Cookie**
- **T1621 - Multi-Factor Authentication Request Generation**
- **TA0007 - Discovery**
- **T1082 - System Information Discovery** (Adaptive UI styling based on OS)
## Functionality
### Core Capabilities
- **Adaptive Interface:** The phishing kit automatically detects the victim's operating system (Windows, macOS, iOS, Android) and browser to render a pixel-perfect fake login window (iframe) that matches the host OS style.
- **BitB Implementation:** Creates a fake browser window inside the legitimate tab, complete with a spoofed address bar showing `accounts.google.com` or other trusted domains.
- **MFA Interception:** Supports real-time prompts for SMS codes, TOTP (Authenticator) codes, Okta push notifications, and Google approval prompts.
- **Real-time Operator Control:** Uses **Socket.IO** to allow a human attacker to interact with the victim, manually triggering password re-entry requests (up to 3 times) or holding the victim on a "waiting" screen while they use the stolen credentials.
### Advanced Features
- **Modern Web Stack:** Built using Next.js and Socket.IO, often hosted on Vercel frontends with Railway or Render backends to avoid traditional domain reputation filters.
- **Evasive Communication:** Unlike transparent reverse proxies (e.g., Evilginx), this platform locally rebuilds the provider interface. API traffic appears to be legitimate communication between an AI tool and its own backend.
- **Broad Lure Selection:** Beyond AI tools (fake "Muse" AI agent), the campaign uses lures related to recruitment opportunities and refund pages.
## Indicators of Compromise
- **File Names:** N/A (Web-based attack).
- **Network Indicators:**
- `accounts.google.com` (Spoofed inside iframe)
- `vercel[.]app` (Subdomains used for hosting)
- `railway[.]app` (Backend API)
- `render[.]com` (Backend API)
- *Note: Specific phishing domains vary frequently; defenders should look for abnormal iframe behavior on AI-related marketing sites.*
- **Behavioral Indicators:**
- Outbound WebSocket (Socket.IO) traffic to non-standard backends during a login process.
- Presence of iframes that cannot be dragged outside the main browser viewport or resized.
## Associated Threat Actors
- **Unknown:** Currently tracked as a financially motivated operation targeting media buyers and ad administrators.
## Detection Methods
- **Behavioral Detection:** Monitor for "window-in-window" behavior where an internal iframe mimics browser UI elements (maximize/minimize/address bar).
- **Network Inspection:** Identify Socket.IO traffic directed toward common PaaS providers (Vercel, Railway) originating from login pages.
- **UI Interaction:** Test the "Connect" pop-up; if it cannot be dragged off-screen or outside the parent window, it is a BitB attack.
## Mitigation Strategies
- **Hardware Security Keys:** Use FIDO2/WebAuthn-compliant hardware keys (e.g., YubiKey) which are resistant to BitB/AiTM attacks because the credential is tied to the actual origin domain.
- **Browser Security Tools:** Employ Enterprise Browser solutions or extensions that detect and block unauthorized iframes or credential inserts on untrusted sites.
- **User Awareness:** Train staff to attempt to "drag" login pop-ups; if the window is clipped by the browser border, it is fraudulent.
- **Password Managers:** Legitimate password managers will generally not auto-fill credentials into a BitB iframe because the top-level domain does not match the stored entry.
## Related Tools/Techniques
- **Evilginx2 / Muraena:** Transparent reverse-proxy phishing kits.
- **mr. dox BitB Framework:** The original open-source proof-of-concept for this technique.
- **Robin Banks:** A Phishing-as-a-Service (PaaS) platform with similar capabilities.