Urgent.News

What's breaking now, across thousands of outlets.

Tech

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

Wiley fisherfolk spin up a new page just days after Meta's AI agent launch

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

A phishing campaign targeting advertising managers is using a fake Meta Muse Ads lure to steal credentials and multi-factor authentication (MFA) codes, just eight days after Meta launched its personal AI agent. The campaign has been identified by security researchers at Island, who discovered a convincing website called museads.ai for a product called Muse Ads.

The operators have adapted the platform, created to lure users into browser-in-the-browser (BitB) attacks, into a new brand in just minutes. Each fake product page has its own "connect" button, which opens a fake browser to steal credentials when users type them in. The BitB technique involves building a fake login window inside a legitimate one, and the fake window looks identical to the real thing.

The scam has been successful, with hundreds of victim submissions reported over a month, and the campaign is still ongoing. The operators use the same platform across many similar sites, estimating the campaign-wide volume to be substantially higher. Victims may face loss of access to advertising accounts, unauthorized ad spend, and exposure of linked client accounts.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Wednesday 7 October →