Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
Yuniawan Tri Cahyono

Empowering Cybersecurity Through Intelligent Automation.

Yuniawan Tri Cahyono

Empowering Cybersecurity Through Intelligent Automation.

  • Home
  • Topics
    • IT Security
      • GRC
        • Identity & Access Management
      • CyberSecurity
        • Defensive Security
          • Incident Response
          • Security Monitoring
            • SIEM
            • SOAR
          • Security Operations
            • Data Protection
            • Security Automation
        • Offensive Security
          • Cyber Threat Hunting
          • Phishing
          • Red Team
          • Threat & Vulnerability
          • Vulnerability Research
    • IT Infrastructure
      • Cloud & Virtualization
      • DevSecOps
      • Linux Security
      • Network Infrastructure
        • Network Operations
        • Network Security
        • Routing & Switching
      • Windows Security
    • Application Security
    • Cloud Security
    • Cryptography & Key Management
    • Maintenance Services
  • Home
  • Topics
    • IT Security
      • GRC
        • Identity & Access Management
      • CyberSecurity
        • Defensive Security
          • Incident Response
          • Security Monitoring
            • SIEM
            • SOAR
          • Security Operations
            • Data Protection
            • Security Automation
        • Offensive Security
          • Cyber Threat Hunting
          • Phishing
          • Red Team
          • Threat & Vulnerability
          • Vulnerability Research
    • IT Infrastructure
      • Cloud & Virtualization
      • DevSecOps
      • Linux Security
      • Network Infrastructure
        • Network Operations
        • Network Security
        • Routing & Switching
      • Windows Security
    • Application Security
    • Cloud Security
    • Cryptography & Key Management
    • Maintenance Services
Close

Search

  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Subscribe
Home/IT Security/Fake ChatGPT, Gemini, and Claude Ad Portals Steal Data
IT SecurityOffensive SecurityPhishing

Fake ChatGPT, Gemini, and Claude Ad Portals Steal Data

By Yuniawan Tri Cahyono
October 7, 2026 4 Min Read
0

Fake AI ad portals are targeting enterprise users by tricking them with malicious advertisements for popular platforms like ChatGPT, Gemini, and Claude. Cybercriminals leverage sponsored search results and social media campaigns to distribute sophisticated phishing portals that harvest corporate credentials and Multi-Factor Authentication (MFA) codes in real time.

As artificial intelligence tools become standard in the workplace, threat actors pivot their strategies. Employees often search for productivity enhancements, making them prime targets for credential harvesting campaigns. This article explores the anatomy of these AI-themed ad scams, examines the underlying mechanics of adversary-in-the-middle attacks, and provides actionable hardening strategies for security teams.

Fake AI Ad Portals and the Anatomy of the Scam

Modern social engineering campaigns have evolved far beyond poorly worded phishing emails. Threat actors now exploit digital advertising networks to bypass traditional perimeter defenses. By purchasing sponsored keyword placements on major search engines, attackers ensure their malicious landing pages appear at the absolute top of search results. Users searching for legitimate tools frequently click these fraudulent links without hesitation.

These fake portals mimic authentic login pages with frightening precision. Every visual element, from branding elements to user interface typography, replicates official vendor platforms. Unsuspecting victims input their enterprise credentials under the assumption that they are authenticating into an official productivity environment. According to recent research highlighted by The Hacker News, these campaigns have successfully compromised numerous corporate networks worldwide.

How Fake ChatGPT, Gemini, and Claude Ad Portals Operate

Execution begins when a victim clicks a sponsored advertisement. The browser redirects through several tracking domains designed to obfuscate the final destination and evade automated security scanners. Once the user lands on the rogue infrastructure, a reverse-proxy framework captures traffic dynamically. This technique allows attackers to relay authentication requests directly to authentic identity providers while intercepting sensitive data streams.

Security administrators must understand that traditional static phishing pages are becoming obsolete. Modern attackers deploy adversary-in-the-middle frameworks to defeat standard security controls. When a user logs in, the proxy intercepts the session cookies instantly. This capability grants threat actors immediate access to corporate environments, bypassing traditional perimeter defenses entirely.

Capturing Credentials and MFA Codes in Real Time

Capturing static passwords is no longer sufficient for sophisticated cybercriminals. Because most organizations mandate Multi-Factor Authentication, threat actors utilize advanced tooling to steal dynamic verification codes. As the victim enters an Authenticator token or SMS code, the reverse-proxy relays that exact token to the legitimate service simultaneously.

Consequently, the attacker gains authenticated session access before the token expires. Organizations relying solely on basic MFA protocols remain critically vulnerable to these transparent proxy attacks. Security teams must evaluate whether their current authentication posture protects against session hijacking and real-time interception.

Mitigating Risks and Protecting Enterprise Infrastructure

Defending against advanced social engineering requires a multi-layered defense strategy. Technical controls must complement rigorous employee awareness training. Security leaders should review their external threat intelligence feeds regularly to identify newly registered lookalike domains targeting their brand or popular software vendors.

Furthermore, implementing advanced endpoint detection and response solutions helps flag anomalous browser activities. IT administrators should also enforce strict web filtering policies and restrict unauthorized software installations across corporate endpoints. For deeper insights into safeguarding enterprise systems, explore our Cyber Security archive.

Implementing Phishing-Resistant Authentication

Phishing-resistant authentication serves as the ultimate barrier against credential harvesting campaigns. Organizations must migrate away from vulnerable verification methods like SMS, push notifications, and standard OTP codes. FIDO2-compliant security keys and passkeys bind authentication directly to the origin domain, rendering adversary-in-the-middle proxies completely ineffective.

When an employee uses a hardware security key, the cryptographic challenge succeeds only if the browser connects to the legitimate domain. Even if an attacker deploys a convincing fake portal, the browser refuses to release the credential. Deploying passkeys across the enterprise neutralizes the threat of real-time code interception entirely.

Enhancing Employee Awareness and DNS Filtering

Human error remains a significant factor in successful security breaches. Security awareness programs must educate staff about the dangers of clicking sponsored search results. Employees should bookmark frequently used productivity tools rather than relying on search engines for daily navigation.

Additionally, network administrators should deploy robust DNS filtering solutions to block newly registered domains and known malicious ad networks. Proactive monitoring ensures that unauthorized connections are intercepted before users reach malicious landing pages. For additional guidance on reinforcing network defenses, read more on our Network Security tag page.

Conclusion

Malicious ad portals exploiting artificial intelligence brands represent a severe threat to modern enterprises. Attackers continue to refine their tactics, bypassing conventional security measures through sophisticated proxy frameworks. Organizations must respond by adopting phishing-resistant credentials, robust DNS filtering, and continuous employee training.

Security practitioners need to act decisively today. Audit your current identity infrastructure, eliminate vulnerable authentication methods, and deploy advanced monitoring tools immediately to protect your corporate assets from evolving threats.

Tags:

AIAI Cyber ThreatsAI CybersecurityAI ThreatsAuthentication SecurityMFAPhishing
Author

Yuniawan Tri Cahyono

Cybersecurity and IT Infrastructure Architect designing secure, automated, and scalable environments. From enterprise-level system monitoring to AI-driven workflows and proactive threat mitigation, I build resilient tech ecosystems. Explore structured insights on IT operations, strategic security, and smart automation designed to future-proof your infrastructure.

Follow Me
Other Articles
Previous

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Next

Atlassian critical flaw threatens eight enterprise tools

No Comment! Be the first one.

Leave a Reply Cancel reply

You must be logged in to post a comment.

Copyright 2026 — Yuniawan Tri Cahyono. All rights reserved. Blogsy WordPress Theme