Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials
A phishing campaign targeting advertising managers by impersonating Gemini, Claude, ChatGPT, Perplexity, and Manus to steal credentials and multi-factor authentication (MFA) codes has added a fake Muse Ads product to its lure lineup – just eight days after Meta launched its personal AI agent. Meta announced Muse on September 8, and by September 17, a very convincing website – museads.ai – for a product called Muse Ads that promised to help advertisers reach buyers and run sponsored placements popped up online. “The operators already had the platform, so adapting it to a new brand can take minutes,” Oleg Zaytsev, lead security researcher at Island, told The Register. “The striking part is how quickly they turned a timely announcement into a credible reason for someone to act. The same platform could then be repackaged around other familiar tasks, from connecting a business tool to claiming a refund or applying for a job.” …
You're reading a preview. The full article is published by The Register on their website.
Read the full story on The Register
