Urgent.News

What's breaking now, across thousands of outlets.

Tech

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

Wiley fisherfolk spin up a new page just days after Meta's AI agent launch

Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials

A phishing campaign targeting advertising professionals by impersonating popular AI platforms Gemini, Claude, ChatGPT, Perplexity, and Manus has added a fake Meta Muse Ads product to its tactics. Meta unveiled Muse on September 8, and just eight days later, a convincing website for Muse Ads emerged online. The operators behind the scam quickly adapted the platform to a new brand, turning a timely announcement into a credible reason for people to act.

The new Muse Ads page served as a lure for browser-in-the-browser (BitB) attacks aimed at stealing advertising credentials, payment methods, and client accounts from agency staff, media buyers, and manager-account administrators. The BitB technique involves creating a fake login window inside a legitimate one, with a convincing address bar, title, and URL.

When the victim clicks the "connect" button, it opens an overlay window stealing credentials while the real browser stays on the phishing domain. The campaign has reportedly observed hundreds of victim submissions over a month, with each ad product having its own page and a "connect" button. The phishing kit supports Google, Meta, TikTok, and Okta workflows, adapting to the victim's browser and operating system.

The operators have exposed older source code through misconfigured public GitHub repositories, linking the campaign to a larger operation. To combat the threat, security teams should maintain a baseline of trusted domains, verify real browser addresses, and monitor similar behavior across different sites.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Wednesday 7 October →