Is Your Ad Portal Real? the Rising Threat of Ai-Themed Credential Phishing Scams
Traditional phishing pages relied on static forms that captured a username and password before redirecting the victim to an error page. Modern digital ad credential phishing scams run on sophisticated Adversary-in-the-Middle (AiTM) frameworks like Evilginx and Modlishka. When an advertiser clicks a spoofed result while searching for a TikTok for Business login, the server acts as an invisible relay between the user and the real platform.
The victim sees a pixel-perfect replica of the authentication portal, complete with functional corporate branding and dynamic language toggles. When the user enters their password, the proxy passes those credentials directly to the authentic platform. The legitimate platform generates an authentication prompt, which the proxy instantly relays back to the user's screen. As soon as the user enters their code, the proxy forwards it to complete the login, captures the resulting session cookie, and hands it directly to the attacker. Through this MFA code interception technique, the adversary acquires a valid, authenticated session without ever needing to crack cryptographic keys.
Once armed with these session tokens, attackers bypass standard password resets entirely. They inject the stolen cookies into an antidetect browser, gaining identical permissions to the compromised account manager. Because the session originated through a legitimate handshake, automated anomaly monitors often register the breach as an ordinary browser reconnect.