Sealzi / JournalStoriesAboutWhat's Vauz? Support

Fake AI ad tools are drawing a whole Google sign-in window inside the page. The address bar in the picture is part of the picture.

All stories ↗

On October 6, Island’s security researchers published a teardown of a phishing operation dressed up as a whole catalogue of AI advertising tools. There’s a ChatGPT one that promises a “Monday Google Ads brief”, a Gemini one with “MCC (manager account) and linked-client support”, plus Claude, Perplexity and Manus versions. When Meta announced its Muse AI on September 8, the scammers had “Muse Ads” running on museads.ai by September 16. Eight days from press release to phishing kit. Nobody at Meta was consulted, we assume 🙄

Every one of these products is built around a single button: Connect. Click it and a Google sign-in window pops up, address bar and all, reading accounts.google.com. Except it isn’t a window, and it isn’t Google. It’s a picture of a browser, drawn inside the web page you’re already on, while your real browser sits on the phishing site the whole time

So what is a browser-in-the-browser?

The trick has been public since 2022 and it’s almost insultingly simple. A real “Sign in with Google” popup is a second browser window with its own address bar, and that address bar is drawn by your browser. A web page can’t touch it. So a phishing page skips the real window and paints a fake one: a box with a title bar, a lock icon, a grey strip that says accounts.google.com, and Google’s sign-in form inside. It sits on top of the page and looks exactly like what you expected to see after clicking “Connect”

Island’s own line on it is the best summary we’ve read: “A page can draw an address bar, lock icon, browser tab, QR prompt, or security dialog. It cannot change the real browser origin”

The address you should trust is the one at the very top of your screen, in your browser’s own toolbar. Everything below that line belongs to the website, including any toolbars the website felt like drawing for you

A real sign-in popup

museads.ai
accounts.google.com
  • Both address bars drawn by your browser
  • Its own window, so it can leave the page

A drawn sign-in window

museads.ai
accounts.google.com
  • Only the top bar is your browser's
  • The inner bar is part of the page
Same page, same-looking window. On the left the address bar on the sign-in window is your browser's, and the window can leave the page. On the right it's a picture inside museads.ai, and only the bar at the very top tells the truth.

What happens after you type your password

This is where it stops being a static fake page and turns into a call centre. According to Island, a human operator sits behind the platform and decides, in real time, what you see next. The form has room for three password attempts. The operator can reject a correct password, tell you it was wrong, ask you to try again, and keep every version you typed (in case you have a “work” one and a “personal” one, presumably)

Then the two-factor part. The operator picks which challenge to show you: an SMS code, an authenticator code, a Google approval prompt, a Google QR verification, a “tap the matching number” screen, an Okta push or an Okta authenticator code. Whatever your account uses, they’ve drawn a picture of it. One of the operator’s commands is literally called /wrong2fa, so they can tell you your perfectly good code was wrong and ask for a fresh one 🤷‍♂️

Meanwhile the page fingerprints your device, “IP and location down to screen size and WebGL”, so the login from their side can look a bit more like it’s coming from you

Island counted 73 phishing domains and 29 back-end servers, saw “hundreds of victim submissions”, and says the operation was still running when they published

Why advertisers, and why job hunters

The targets are people who run ad accounts: in-house marketers, agency staff, media buyers. One Google Ads manager account can reach a lot of client accounts, each with a saved payment method and an approved budget. Steal one login and a whole row of other people’s budgets is in reach. Very efficient, very entrepreneurial 🤑

There’s a second lane aimed at job applicants. Island’s point is a nasty one: someone looking for a job usually still has one, and may sign in to a “recruiting portal” with their work Google or Okta account. So one fake job ad can open their current employer’s email and files

How to spot a fake sign-in window

Most of this comes down to remembering that a real popup is a real window, and a fake one is part of the page

And the real fix for the account itself is the one Island ends on. Passkeys and hardware security keys are tied to the real site, so a passkey for Google simply won’t work on museads.ai. There’s no password or one-time code in the flow for anyone to type into the wrong box. If your ad account or work account offers passkeys, turn them on today. Boring, and right

The tell that doesn’t care how good the picture is

Every check above relies on a human noticing something, on a busy day, while a page is doing its best to look normal. This one doesn’t

Vauz  asks the browser where the page really is. Not what the page says. Not what’s written in the little grey bar it drew for you. The browser’s own answer, which a page can’t change. On museads.ai, the answer is museads.ai, and Vauz only offers a login on the exact site it was saved for. Your Google login was saved for Google. So the fake window can be pixel-perfect and Vauz still won’t give it your Google password 🫥

You’ll see that before you type a thing. Click the Vauz logo on the fake form and the approval prompt pops up from the Vauz app, outside the browser, naming the site you’re really on: museads.ai, not Google. Approve it anyway (please don’t, never approve a site you didn’t expect to be on) and Vauz tells you there are no credentials for that domain. And if the fake window is built as a frame embedded in the page, Vauz doesn’t touch it at all, because it never fills inside embedded frames. That approval prompt is the same one we wrote about in clickjacking attacks on autofill

That’s the warning. If the sign-in window says Google but the Vauz prompt names some other site, believe Vauz: the window is fake. The mistake is reaching for the copy button and pasting the password in by hand because “autofill is being weird again”. Autofill isn’t being weird. It’s the only thing in the room reading the real address

On the fake window

Looks like (Vauz ignores this)accounts.google.com
Your browser reportsmuseads.ai
Logins saved for that exact siteNone
VauzNothing to offer

On the real Google sign-in page

Looks like (Vauz ignores this)accounts.google.com
Your browser reportsaccounts.google.com
Logins saved for that exact siteYour Google login
VauzOffers it once you approve
Vauz never reads the address a page draws. It asks the browser, and only looks for logins saved for that exact site, so on museads.ai your Google login doesn't come up however good the picture is.

That covers your password. It doesn’t cover the SMS code, the authenticator code or the Okta push, which you’d still be typing or tapping by hand into a box drawn by a stranger. Keeping the password out of the wrong box and putting passkeys on the accounts that matter are two different jobs, and you want both

There’ll be another fake AI tool next week

The lure here was AI, and it’ll keep being AI for a while, because every week brings a new AI product with a “Connect your account” button and nobody can keep track of which ones are real. We’ve already written about AI agents signing in with your saved passwords and about extensions forwarding live sessions. Scammers posing as an AI tool are just the lowest-effort version of the same idea: get you to hand over a login because the button said “Connect”

So next time a brand-new AI tool wants you to “Connect” your Google account, look it up on its maker’s own site first. And if the sign-in window says Google while Vauz names some other site, close the tab 🫡

Filled by the real address

Vauz fills a login only on the site it was saved for.

Vauz reads the address the way your browser sees it, not the way a page draws it, and fills a saved login only on that exact site. A Google login won't turn up on a page that only looks like Google. The free plan stays completely free for life, with Plus and Premium available when you need more!

Use Vauz completely free — for, like, ever
© 2026 Sealzi. Where privacy matters.Sealzi.com ↗Vauz ↗RSS