Browser-in-browser attacks use fake Meta Muse Ad lure to steal credentials
A phishing campaign has rapidly adapted to exploit Meta's newly launched Muse product, creating a fake "Muse Ads" website just eight days after the company's announcement on 8 September. The attack uses sophisticated browser-in-browser overlays that mimic genuine login pages to steal credentials and multi-factor authentication codes from advertising professionals. This swift adaptation demonstrates how criminals exploit the publicity surrounding new product launches to lend credibility to their scams.
Security researchers at Island discovered that the same criminal platform has previously impersonated Gemini, Claude, ChatGPT, Perplexity, and Manus. One frontend alone received submissions from roughly 200 distinct email addresses over approximately one month, with researchers estimating the campaign's overall volume is substantially higher. The attacks specifically target agency staff, media buyers, and manager-account administrators, putting them at risk of losing access to accounts, facing unauthorised ad spending, and exposing linked client accounts to theft.
- Scammers created fake Muse Ads site just eight days after Meta's launch
- Browser-in-browser overlays mimic real login pages to steal credentials
- One campaign frontend targeted roughly 200 distinct email addresses
New here? Start with this
Meta Muse is a newly launched product from Meta that was announced in September 2026. Criminals quickly created a fake "Muse Ads" website designed to look identical to the real one. When people tried to log in through this fake site, the scammers captured their login details and security codes.
The attacks specifically target people who work in advertising, including agency staff and media buyers who manage advertising accounts. If these professionals fall for the scam, criminals can access their accounts, spend money without authorisation, and potentially steal information from their clients' accounts. This represents a significant financial and security risk to both the individual and the organisations they work for.
This pattern is not new. Security researchers have found that the same criminal group has previously created fake versions of other newly launched products and services, including artificial intelligence tools. By striking quickly after a product launch, when media attention and user curiosity are high, the scammers are able to make their fake sites appear credible.