Threat actors are now abusing Google’s Firebase App Distribution service to push fake Android ChatGPT and Meta advertising apps that steal Facebook credentials and enable account takeover.
The operation closely mirrors a recent iOS phishing campaign that used bogus ChatGPT and Gemini apps, but this wave specifically targets Android users through invitation-style emails that appear to come from Google’s infrastructure.
The campaign begins with invitation emails that claim to offer early access to AI‑powered advertising or ChatGPT tools for Android.
These messages reference app “testing” or “beta access,” mimicking the language legitimate developers use when onboarding testers.
The emails are sent via the address “[email protected],” a legitimate notification channel for Firebase App Distribution, which makes the messages look authentic to many recipients.
In the email, victims are prompted to click a “Get started” or “Install” button that takes them to a Firebase App Distribution landing page.
This page is hosted on Google infrastructure and presents the app as an OpenAI, ChatGPT, or Meta Ads-related testing build, complete with version numbers and brief release notes.
The notes frequently mention ad credit promotions, “$200 bonus” offers, or advanced advertising automation features designed to attract marketers and Facebook page admins.
Researchers note that this Android activity follows an earlier campaign where phishing emails pushed fake ChatGPT and Gemini iOS apps from the official Apple App Store, also used to steal Facebook logins via embedded fake login screens.
Fake Android Apps and Facebook
Once the victim sideloads the Android package from Firebase, the installed app’s behavior diverges sharply from the advertised functionality.
Instead of delivering AI assistants or ad‑management dashboards, the app immediately loads a webview that presents a Facebook login screen.
The interface closely mimics the official Facebook mobile login page, including branding and layout, leaving most users unaware they are interacting with a phishing component rather than the real app.
When the user submits their email, phone number, and password, the credentials are sent to attacker‑controlled servers instead of Facebook.
In some observed cases, the app also prompts for two‑factor authentication codes or business manager verification steps, harvesting tokens that allow bypass of security controls.
With valid credentials in hand, threat actors can seize control of personal profiles, business pages, and ad accounts, often using them to run fraudulent ad campaigns or spread additional malware.
In both cases, criminals lean on the trust placed in well‑known AI brands and in official or semi‑official distribution channels such as TestFlight, the App Store, and Firebase App Distribution.
This pattern shows a clear evolution from simple phishing sites to abuse of legitimate software supply and testing ecosystems to increase victim confidence and bypass security filters.
Mitigations
Android users should treat any unsolicited testing invitation for ChatGPT, Meta Ads, or similar AI tools with suspicion, even when messages appear to originate from Google services.
They should avoid sideloading APKs from email links and instead obtain ChatGPT or Meta apps only through the official Google Play Store or verified corporate channels.
Organizations that manage Facebook business assets should enforce multi‑factor authentication, monitor for unusual ad spend or login locations, and educate staff that Facebook and OpenAI will not distribute paid advertising tools via random Firebase or TestFlight invitations.
Security teams should also tune email gateways and mobile device management policies to flag Firebase distribution links in unsolicited campaigns and restrict sideloading on managed Android devices where possible.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





