đïž Contexte
PubliĂ© le 7 octobre 2026 sur Cryptika (source originale : CyberSecurityNews.com), cet article relaie un rapport des chercheurs Oleg Zaytsev et Ofek Ronen d’Island.io, publiĂ© le 6 octobre 2026. Il documente une campagne active de phishing ciblant les gestionnaires de comptes publicitaires en ligne.
đŻ Nature de l’attaque
La campagne repose sur l’usurpation d’identitĂ© de plateformes IA (ChatGPT, Claude, Gemini, Perplexity, Manus, Muse Ads) pour attirer des victimes vers de faux portails publicitaires. Les leurres incluent :
- Des emails d’invitation promettant des audits de campagnes, des bilans de dĂ©penses ou des connexions de comptes
- Des pages imitant des outils lĂ©gitimes d’IA pour la gestion publicitaire
- Un leurre de recrutement (Tesla, Ferrari, Apple, Louis Vuitton, Nike, Adecco, Red Bull)
đ„ïž Technique Browser-in-the-Browser (BitB)
Au lieu d’un tĂ©lĂ©chargement de malware, la campagne utilise la technique Browser-in-the-Browser : une fausse fenĂȘtre de navigateur est dessinĂ©e Ă l’intĂ©rieur du vrai navigateur, reproduisant une barre d’adresse et un cadenas convaincants, tout en restant sur une infrastructure contrĂŽlĂ©e par l’attaquant. Cette imitation s’adapte Ă Windows, macOS, iOS et Android, incluant le mode sombre et les contrĂŽles mobiles.
đ Collecte des identifiants et MFA
La plateforme :
- Enregistre les caractĂ©ristiques de l’appareil, la localisation et les identifiants soumis
- Conserve trois tentatives de mot de passe distinctes (champs
password_one,password_two,password_three) - Permet Ă des opĂ©rateurs humains en temps rĂ©el de choisir le prochain dĂ©fi d’authentification via des commandes Telegram
- Supporte : codes SMS, codes d’authentificateur, approbations Google, vĂ©rification QR, number matching, push Okta
đïž Infrastructure partagĂ©e
L’infrastructure commune repose sur Next.js et Socket.IO et supporte simultanĂ©ment les leurres publicitaires IA, les fausses demandes de remboursement et les faux sites de recrutement. Les chercheurs ont liĂ© un backend Ă 73 scans archivĂ©s couvrant 25 domaines entre le 27 mai et le 20 juin. Du code source exposĂ© sur des dĂ©pĂŽts GitHub publics a rĂ©vĂ©lĂ© les routes, le modĂšle de triple tentative de mot de passe et les contrĂŽles Telegram.
đ° Impact potentiel
Les comptes publicitaires compromis peuvent :
- Financer des campagnes frauduleuses
- Ătre revendus Ă d’autres criminels
- Exposer plusieurs clients, leurs profils de facturation et budgets publicitaires approuvés
- Permettre aux attaquants d’ajouter leurs propres administrateurs et de rĂ©duire l’accĂšs lĂ©gitime
đ Type d’article
Il s’agit d’une publication de recherche relayĂ©e par la presse spĂ©cialisĂ©e, visant Ă documenter une campagne active, partager les IoCs et les artefacts de dĂ©tection pour permettre une rĂ©ponse opĂ©rationnelle immĂ©diate.
đ§ TTPs et IOCs dĂ©tectĂ©s
TTP
- T1566.002 â Phishing: Spearphishing Link (Initial Access)
- T1056.003 â Input Capture: Web Portal Capture (Collection)
- T1539 â Steal Web Session Cookie (Credential Access)
- T1557 â Adversary-in-the-Middle (Credential Access)
- T1185 â Browser Session Hijacking (Collection)
- T1598.003 â Phishing for Information: Spearphishing Link (Reconnaissance)
- T1078 â Valid Accounts (Defense Evasion)
- T1586.002 â Compromise Accounts: Email Accounts (Resource Development)
- T1583.001 â Acquire Infrastructure: Domains (Resource Development)
- T1102 â Web Service (Command and Control)
IOC
- Domaines :
account-sync-data.comâ VT · URLhaus · ThreatFox - Domaines :
ads-claude-beta.comâ VT · URLhaus · ThreatFox - Domaines :
ads-claude.comâ VT · URLhaus · ThreatFox - Domaines :
ads-team-openai.comâ VT · URLhaus · ThreatFox - Domaines :
adsmistral.comâ VT · URLhaus · ThreatFox - Domaines :
advertising-chatgpt.comâ VT · URLhaus · ThreatFox - Domaines :
advertising-gemini.comâ VT · URLhaus · ThreatFox - Domaines :
ai-ads-platform.comâ VT · URLhaus · ThreatFox - Domaines :
ai-brand-safety.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-ads-beta.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-ads-marketing.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-ads.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-beta-ads.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-crm-1.comâ VT · URLhaus · ThreatFox - Domaines :
anthropic-sponsored.comâ VT · URLhaus · ThreatFox - Domaines :
beta-anthropic.comâ VT · URLhaus · ThreatFox - Domaines :
beta-chatgpt.comâ VT · URLhaus · ThreatFox - Domaines :
beta-gemini-ads.comâ VT · URLhaus · ThreatFox - Domaines :
beta-manus.comâ VT · URLhaus · ThreatFox - Domaines :
beta-perplexity.comâ VT · URLhaus · ThreatFox - Domaines :
business-gemini.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-advertise.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-advertisement.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-beta.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-brief.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-briefing.comâ VT · URLhaus · ThreatFox - Domaines :
chatgpt-monday-brief.comâ VT · URLhaus · ThreatFox - Domaines :
claude-ads-beta.comâ VT · URLhaus · ThreatFox - Domaines :
claude-ads-invitations.comâ VT · URLhaus · ThreatFox - Domaines :
claude-ads-portal.comâ VT · URLhaus · ThreatFox - Domaines :
claude-ads.aiâ VT · URLhaus · ThreatFox - Domaines :
claude-advertisement.comâ VT · URLhaus · ThreatFox - Domaines :
claude-advertisers.aiâ VT · URLhaus · ThreatFox - Domaines :
claude-advertisers.comâ VT · URLhaus · ThreatFox - Domaines :
claude-beta-invite.comâ VT · URLhaus · ThreatFox - Domaines :
claude-beta.comâ VT · URLhaus · ThreatFox - Domaines :
cursor-ads.comâ VT · URLhaus · ThreatFox - Domaines :
escrow-ads.comâ VT · URLhaus · ThreatFox - Domaines :
gemimi-ads.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-ads-ai.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-ads-invite.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-ads-team.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-ads.aiâ VT · URLhaus · ThreatFox - Domaines :
gemini-advertisers.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-beta-invitations.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-beta-invites.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-business.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-google-ads.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-invitation.comâ VT · URLhaus · ThreatFox - Domaines :
gemini-invitations.comâ VT · URLhaus · ThreatFox - Domaines :
gennini-ads.comâ VT · URLhaus · ThreatFox - Domaines :
google-ads-sync.comâ VT · URLhaus · ThreatFox - Domaines :
invitation-anthropic.comâ VT · URLhaus · ThreatFox - Domaines :
leaks-entry.comâ VT · URLhaus · ThreatFox - Domaines :
leaksentry-security.comâ VT · URLhaus · ThreatFox - Domaines :
link-mcc.comâ VT · URLhaus · ThreatFox - Domaines :
manus-meta.imâ VT · URLhaus · ThreatFox - Domaines :
manusbymeta.comâ VT · URLhaus · ThreatFox - Domaines :
manusmeta.imâ VT · URLhaus · ThreatFox - Domaines :
mcc-account-sync.comâ VT · URLhaus · ThreatFox - Domaines :
mcc-invitation.comâ VT · URLhaus · ThreatFox - Domaines :
mcc-safety.comâ VT · URLhaus · ThreatFox - Domaines :
mcc-security.comâ VT · URLhaus · ThreatFox - Domaines :
mcc-verification.comâ VT · URLhaus · ThreatFox - Domaines :
metamanus.imâ VT · URLhaus · ThreatFox - Domaines :
monday-brief-claude.comâ VT · URLhaus · ThreatFox - Domaines :
museads.aiâ VT · URLhaus · ThreatFox - Domaines :
openai-ads.aiâ VT · URLhaus · ThreatFox - Domaines :
openai-advertisers.comâ VT · URLhaus · ThreatFox - Domaines :
openaiadsteam.comâ VT · URLhaus · ThreatFox - Domaines :
perplexity-advertising.comâ VT · URLhaus · ThreatFox - Domaines :
perplexity-beta-ads.comâ VT · URLhaus · ThreatFox - Domaines :
perplexity-beta.comâ VT · URLhaus · ThreatFox - Domaines :
safety-mcc.comâ VT · URLhaus · ThreatFox - Domaines :
security-ads.comâ VT · URLhaus · ThreatFox - Domaines :
security-mcc.comâ VT · URLhaus · ThreatFox - Domaines :
semrush-ai.comâ VT · URLhaus · ThreatFox - Domaines :
semrushads-ai.comâ VT · URLhaus · ThreatFox - Domaines :
sponsored-gemini.comâ VT · URLhaus · ThreatFox - Domaines :
sync-account-invite.comâ VT · URLhaus · ThreatFox - Domaines :
sync-account.comâ VT · URLhaus · ThreatFox - Domaines :
sync-ads-account.comâ VT · URLhaus · ThreatFox - Domaines :
sync-ads.comâ VT · URLhaus · ThreatFox - Domaines :
sync-business.comâ VT · URLhaus · ThreatFox - Domaines :
sync-mcc-account.comâ VT · URLhaus · ThreatFox - Domaines :
sync-mcc-data.comâ VT · URLhaus · ThreatFox - Domaines :
sync-mcc-team.comâ VT · URLhaus · ThreatFox - Domaines :
sync-tiktok.comâ VT · URLhaus · ThreatFox - Domaines :
verification-security.comâ VT · URLhaus · ThreatFox - Domaines :
confirm-payments.comâ VT · URLhaus · ThreatFox - Domaines :
payment-confirm.comâ VT · URLhaus · ThreatFox - Domaines :
payment-confirmation.comâ VT · URLhaus · ThreatFox - Domaines :
payment-confirmations.comâ VT · URLhaus · ThreatFox - Domaines :
payment-sync.comâ VT · URLhaus · ThreatFox - Domaines :
payments-sync.comâ VT · URLhaus · ThreatFox - Domaines :
refund-advertisers.comâ VT · URLhaus · ThreatFox - Domaines :
sync-billing.comâ VT · URLhaus · ThreatFox - Domaines :
sync-payment.comâ VT · URLhaus · ThreatFox - Domaines :
sync-payments.comâ VT · URLhaus · ThreatFox - Domaines :
adeccohr-calendly.comâ VT · URLhaus · ThreatFox - Domaines :
adeccohr-jobs.comâ VT · URLhaus · ThreatFox - Domaines :
apple-career.comâ VT · URLhaus · ThreatFox - Domaines :
nikehr-jobs.comâ VT · URLhaus · ThreatFox - Domaines :
talent-louisvuitton.comâ VT · URLhaus · ThreatFox - Domaines :
careers-interview.comâ VT · URLhaus · ThreatFox - Domaines :
ferrar.careers-interview.comâ VT · URLhaus · ThreatFox - Domaines :
ferrari-invite.comâ VT · URLhaus · ThreatFox - Domaines :
redbullapply.careers-appointment.comâ VT · URLhaus · ThreatFox - Domaines :
tesla-careerapplication.comâ VT · URLhaus · ThreatFox - URLs :
https://adsclaudeback-production.up.railway.appâ URLhaus - URLs :
https://anthropicadsback.onrender.comâ URLhaus - URLs :
https://backend-j02u.onrender.comâ URLhaus - URLs :
https://backend-production-6d75.up.railway.appâ URLhaus - URLs :
https://backend-tg0j.onrender.comâ URLhaus - URLs :
https://chatgptadsback-production.up.railway.appâ URLhaus - URLs :
https://chatgptadsback.onrender.comâ URLhaus - URLs :
https://claudeadsback-production-67c1.up.railway.appâ URLhaus - URLs :
https://claudeadsback-production.up.railway.appâ URLhaus - URLs :
https://geminiback-5j1n.onrender.comâ URLhaus - URLs :
https://geminiback-production.up.railway.appâ URLhaus - URLs :
https://just-cooperation-production-f159.up.railway.appâ URLhaus - URLs :
https://manus2back-production.up.railway.appâ URLhaus - URLs :
https://manusback-bahk.onrender.comâ URLhaus - URLs :
https://manusback-production.up.railway.appâ URLhaus - URLs :
https://manusback.onrender.comâ URLhaus - URLs :
https://mbackend-mdye.onrender.comâ URLhaus - URLs :
https://museadsback-production.up.railway.appâ URLhaus - URLs :
https://semrushback.onrender.comâ URLhaus - URLs :
https://syncgadsback.onrender.comâ URLhaus - URLs :
https://syncgoogleadsback-production-6100.up.railway.appâ URLhaus - URLs :
https://syncgoogleadsback-production-cde6.up.railway.appâ URLhaus - URLs :
https://syncgoogleadsback-production.up.railway.appâ URLhaus - URLs :
https://syncgoogleadsback.onrender.comâ URLhaus - URLs :
https://tbackend-production-39ca.up.railway.appâ URLhaus - URLs :
https://nikear.onrender.comâ URLhaus - URLs :
https://zero39172-391920.onrender.comâ URLhaus - URLs :
https://mango-back.onrender.comâ URLhaus
â ïž Ă propos de ces IOC â ils sont extraits automatiquement de l’article original le 7 octobre 2026 et n’ont pas fait l’objet d’une vĂ©rification externe. Un indicateur peut avoir Ă©tĂ© rĂ©attribuĂ© depuis : une IP de C2 peut redevenir un service lĂ©gitime, un domaine sinkholĂ© peut changer de propriĂ©taire. Aucune garantie d’exactitude ni d’actualitĂ© â contrĂŽlez leur validitĂ© avant tout usage opĂ©rationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- Browser-in-the-Browser (BitB) phishing kit (other)
- Socket.IO-based phishing platform (other)
đą Indice de vĂ©rification factuelle : 85/100 (haute)
- â cryptika.com â source reconnue (Rösti community) (20pts)
- â 16400 chars â texte complet (fulltext extrait) (15pts)
- â 137 IOCs (IPs/domaines/CVEs) (10pts)
- â 3/6 IOCs confirmĂ©s (ThreatFox, URLhaus, VirusTotal) (15pts)
- â 10 TTPs MITRE identifiĂ©es (15pts)
- â date extraite du HTML source (10pts)
- ⏠aucun acteur de menace nommé (0pts)
- ⏠pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
account-sync-data.com(domain) â VT (5/92 dĂ©tections)ads-claude-beta.com(domain) â VT (7/92 dĂ©tections)ads-claude.com(domain) â VT (4/92 dĂ©tections)
đ Source originale : https://www.cryptika.com/hackers-use-fake-chatgpt-claude-and-gemini-ads-to-steal-passwords-and-mfa-codes/