Back to Intelligence

BigBear 2.0 Evilginx2 PhaaS + Fake AI Ads BitB Campaign: Credential Theft & Cloud Token-Jacking Wave — OTX Pulse Analysis

SA
Security Arsenal Team
October 7, 2026
8 min read

Threat Summary

Four concurrent OTX pulses paint a coherent picture of the current credential-theft threat landscape: adversaries are industrializing identity compromise across three layers — traditional enterprise identity (Microsoft 365), emerging AI platform identities (Claude, Gemini, ChatGPT ad consoles), and cloud control planes (AWS access keys validated for Amazon Bedrock).

The most operationally mature activity is BigBear 2.0, a rebranded Evilginx2-based phishing-as-a-service framework attributed to operator 'General Boss'. It runs 42 VPS nodes (primarily Vultr) using the 'offy' phishlet, performing adversary-in-the-middle (AiTM) session hijacking against Microsoft 365 tenants across Technology, Energy, Healthcare, Finance, and Government sectors in at least six countries. Because Evilginx2 proxies the real authentication flow, it captures session cookies and defeats standard MFA.

In parallel, the 'Fake AI Ads' campaign uses Browser-in-the-Browser (BitB) fake authentication windows over socket.io-backed phishing pages impersonating Claude, Gemini, ChatGPT, and Perplexity advertising products — human-operated, targeting ad account credentials in Technology and Media verticals.

On the exploitation side, opportunistic scanners (405 attempts from 55 IPs) are hitting CVE-2026-0768, an unauthenticated RCE in Langflow, the first AI/ML dev platform observed in internet-wide exploitation scanning — alongside legacy exploits (ProxyLogon CVE-2021-26855, CVE-2024-4577) suggesting broad shotgun exploitation followed by credential harvesting. Finally, Datadog-observed tooling (KMON_NOC) validates stolen AWS keys via GetCallerIdentity and then probes ListFoundationModels/Converse calls to determine whether keys unlock paid Bedrock LLM access — a 'token-jacking' monetization step that turns any leaked key into resaleable AI compute.

Collective objective: capture reusable identity material (sessions, cookies, cloud keys) and convert it into access, resale, or LLM resource theft.

Threat Actor / Malware Profile

BigBear 2.0 (Evilginx2 PhaaS) — Operator: 'General Boss'

  • Distribution: Phishing emails and lures themed around Microsoft 365 sign-in; domains impersonating legitimate businesses (dronalms.com, ccpipharma.com, knowncontractor.com, etc.) plus URL paths like /meetings to feign collaboration invites.
  • Payload behavior: Evilginx2 acts as a transparent reverse proxy to the real Microsoft login. Victim credentials AND the post-authentication session cookie pass through the attacker's node and are harvested. Geo-matched residential proxies reduce impossible-travel and ASN anomaly detections.
  • C2 communication: 42 VPS nodes, predominantly Vultr; the 'offy' phishlet handles Microsoft endpoints. Session tokens are exfiltrated to operator panels in real time for immediate replay.
  • Persistence: The stolen session cookie itself is the persistence — valid until expiry or revocation, bypassing password resets that don't revoke tokens.
  • Anti-analysis: Geo-fencing, residential proxy egress, per-victim one-time URLs, and legitimately signed TLS on phishing domains defeat URL-scanner sandboxing.

Fake AI Ads Campaign (BitB platform)

  • Distribution: Ads/lures for fake 'AI advertising products' (claude-ads.ai, gemini-advertisers.com, manusbymeta.com).
  • Payload behavior: 'Connect' button spawns a BitB window — a fake OAuth prompt rendered in-page via socket.io — capturing credentials and MFA input while the address bar appears legitimate.
  • Anti-analysis: Human-operated flow, JavaScript-rendered windows invisible to static URL crawlers, brand-impersonation domains with valid certs.

KMON_NOC / AWS Credential Validation Tooling

  • Behavior: sts:GetCallerIdentity to confirm key validity → bedrock:ListFoundationModels and Converse/InvokeModel probes to check for LLM entitlement. Non-destructive, low-noise validation designed to fly under GuardDuty anomaly thresholds.

IOC Analysis

  • Domains (135+ across pulses): PhaaS nodes (dronalms.com, arrmmy.com, captelind.com) and BitB impersonation domains (claude-ads.ai, gemini-ads-team.com, sync-account.com, payment-confirm.com). Operationalize via DNS sinkhole/proxy block and retro-hunt proxy + DNS logs for 90 days. Brand-impersonation domains should also feed domain-monitoring (lookalike registration) pipelines.
  • IPv4 (Bedrock testers): 112.78.151.90, 78.109.78.211, 83.194.172.248, 103.160.185.100, 109.146.93.39, 115.138.247.83 — block at egress and correlate against AWS CloudTrail sourceIPAddress for any IAM activity in your org.
  • FileHash-SHA256 (credential validation tooling): Add to EDR blocklists and retro-hunt; decode/triage samples in a sandbox (ANY.RUN, Hybrid Analysis) to extract embedded panel C2.
  • URLs: Paths like http://management.daengrentacar.com/meetings indicate lure theming — hunt web proxy logs for the full URI, not just host.
  • CVEs: CVE-2026-0768 (Langflow), CVE-2021-26855, CVE-2022-41082, CVE-2024-4577, CVE-2021-34523, CVE-2017-9841, CVE-2018-20062 — feed into vulnerability management; any internet-exposed instance is a drop zone for harvested credential tooling.

Detection Engineering

YAML
---
title: Evilginx2 BigBear 2.0 AiTM Phishing Infrastructure Access
id: 8f3a1c2e-7b4d-4e91-a5c6-2d9f8e1a3b01
status: experimental
description: Detects network connections to known BigBear 2.0 / Evilginx2 PhaaS nodes and fake AI advertising phishing domains observed in OTX pulses
author: Security Arsenal
references:
  - https://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaign
  - https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
date: 2026/10/07
logsource:
  category: dns
detection:
  selection_bigbear:
    query|contains:
      - 'dronalms.com'
      - 'ccpipharma.com'
      - 'knowncontractor.com'
      - 'hnospascualfadon.com'
      - 'annastudios-paros.com'
      - 'arrmmy.com'
      - 'captelind.com'
      - 'daengrentacar.com'
  selection_bitb:
    query|contains:
      - 'sync-account.com'
      - 'verification-security.com'
      - 'payment-confirm.com'
      - 'claude-ads.ai'
      - 'claude-advertisers.ai'
      - 'gemini-ads-team.com'
      - 'gemini-advertisers.com'
      - 'manusbymeta.com'
  condition: 1 of selection_*
falsepositives:
  - Threat research and sandbox detonation
level: high
tags:
  - attack.credential_access
  - attack.t1557
  - attack.t1566.002
---
title: Suspicious AWS Credential Validation for Amazon Bedrock Access
id: 2c7d9e4a-1f6b-4c83-b7e2-5a3d6f9c1e02
status: experimental
description: Detects the KMON_NOC-style validation sequence where stolen AWS keys are tested via GetCallerIdentity followed by Bedrock ListFoundationModels or model invocation, potentially from external infrastructure
author: Security Arsenal
references:
  - https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
date: 2026/10/07
logsource:
  product: aws
  service: cloudtrail
detection:
  selection_bedrock:
    eventSource: 'bedrock.amazonaws.com'
    eventName:
      - 'ListFoundationModels'
      - 'Converse'
      - 'InvokeModel'
  filter_known_automation:
    userIdentity.type: 'AssumedRole'
    userIdentity.principalId|contains: 'deploy-pipeline'
  condition: selection_bedrock and not filter_known_automation
falsepositives:
  - Legitimate developer experimentation with Bedrock from corporate IP ranges
level: medium
tags:
  - attack.discovery
  - attack.t1526
  - attack.t1078.004
---
title: Browser-in-the-BitB Phishing Artifact - Suspicious OAuth Window Spawn
id: 6e1b4a8d-3c9f-4d72-a8e5-7b2c4d6e9f03
status: experimental
description: Detects browsers establishing websocket connections to known fake-AI-ads phishing domains, consistent with the socket.io Browser-in-the-Browser credential theft platform
author: Security Arsenal
references:
  - https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
date: 2026/10/07
logsource:
  category: proxy
detection:
  selection:
    c-uri|contains:
      - 'socket.io'
    cs-host|contains:
      - 'claude-ads.ai'
      - 'claude-advertisers.ai'
      - 'gemini-ads-team.com'
      - 'gemini-advertisers.com'
      - 'manusbymeta.com'
      - 'sync-account.com'
      - 'verification-security.com'
      - 'payment-confirm.com'
  condition: selection
falsepositives:
  - None expected; these domains are confirmed phishing infrastructure
level: critical
tags:
  - attack.credential_access
  - attack.t1556
  - attack.t1566
KQL — Microsoft Sentinel / Defender
// Hunt: Evilginx2/BigBear 2.0 AiTM + BitB phishing access and anomalous M365 sign-ins
let PhishDomains = dynamic(["dronalms.com","ccpipharma.com","knowncontractor.com","hnospascualfadon.com","annastudios-paros.com","arrmmy.com","captelind.com","daengrentacar.com","sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai","claude-advertisers.ai","gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com"]);
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl has_any (PhishDomains)
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, RemoteUrl, RemoteIP, InitiatingProcessFileName;
let SuspiciousSignins = SigninLogs
| where TimeGenerated > ago(30d)
| where ResultType == 0
| summarize FirstToken=arg_min(TimeGenerated, *) by UserPrincipalName, SessionId
| project SigninTime=TimeGenerated, UserPrincipalName, IPAddress, SessionId, UserAgent, AppDisplayName;
NetworkHits
| join kind=leftouter (SuspiciousSignins) on $left.InitiatingProcessAccountName contains tostring($right.UserPrincipalName)
| extend AiTM_Suspect = iff(isnotempty(IPAddress) and IPAddress != RemoteIP, "Possible session replay from different IP", "Review")
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, RemoteUrl, RemoteIP, UserPrincipalName, IPAddress, UserAgent, AiTM_Suspect
| order by TimeGenerated desc;
PowerShell
# Security Arsenal - Credential Theft IOC Hunt (BigBear 2.0 / BitB / AWS key testers)
# Run as admin on endpoints or via EDR live response
$phishDomains = @("dronalms.com","ccpipharma.com","knowncontractor.com","arrmmy.com","captelind.com",`
  "sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai",`
  "gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com")
$badIPs = @("112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83")
$badHashes = @("923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608",`
  "c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc")

Write-Host "=== [1] DNS cache check for phishing domains ===" -ForegroundColor Cyan
Get-DnsClientCache | Where-Object { $e=$_.Entry; $phishDomains | Where-Object { $e -like "*$_*" } } |
  Select-Object Entry, Data, TimeToLive

Write-Host "=== [2] Active/historical connections to AWS-key-tester IPs ===" -ForegroundColor Cyan
Get-NetTCPConnection | Where-Object { $badIPs -contains $_.RemoteAddress } |
  Select-Object LocalAddress, LocalPort, RemoteAddress, State, OwningProcess

Write-Host "=== [3] Hash sweep of common drop locations ===" -ForegroundColor Cyan
$paths = @("$env:TEMP","$env:APPDATA","$env:LOCALAPPDATA\Temp","$env:USERPROFILE\Downloads")
foreach ($p in $paths) {
  Get-ChildItem -Path $p -Recurse -File -ErrorAction SilentlyContinue |
    Where-Object { $_.Length -lt 50MB } |
    ForEach-Object {
      $h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
      if ($badHashes -contains $h) { Write-Host "HIT: $($_.FullName) -> $h" -ForegroundColor Red }
    }
}

Write-Host "=== [4] Browser cache artifacts referencing phishing domains (Chrome) ===" -ForegroundColor Cyan
$chromeCache = "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Cache"
if (Test-Path $chromeCache) {
  Get-ChildItem $chromeCache -Recurse -File -ErrorAction SilentlyContinue | Select-String -List `
    -Pattern ($phishDomains -join '|') -ErrorAction SilentlyContinue |
    Select-Object Path, LineNumber
}

Write-Host "=== [5] AWS CLI credential files present (review for unexpected keys) ===" -ForegroundColor Cyan
Get-ChildItem "$env:USERPROFILE\.aws" -ErrorAction SilentlyContinue | Select-Object FullName, LastWriteTime
Write-Host "Hunt complete. Escalate any HITs to IR immediately." -ForegroundColor Green

Response Priorities

Immediate (0-4h)

  • Block all listed phishing domains and IPv4 indicators at DNS, proxy, and EDR network layers; add SHA256 hashes to EDR blocklists.
  • Retro-hunt 30-90 days of proxy/DNS logs for the PhaaS and BitB domains; any hit = assume credential + session compromise.
  • Audit CloudTrail for GetCallerIdentity, ListFoundationModels, Converse, InvokeModel from non-corporate source IPs (especially the listed IPs).
  • Inventory internet-exposed Langflow instances; block or take offline pending CVE-2026-0768 patch.

24 Hours

  • For any user who visited a phishing domain: revoke all active sessions and refresh tokens (password reset alone is insufficient against Evilginx2 cookie theft), re-register MFA, and review mailbox rules and OAuth app consents.
  • Rotate any AWS keys that show anomalous validation activity; enforce aws:SourceIp and aws:ViaAWSService conditions on key policies; disable unused IAM users.
  • Check Entra ID sign-in logs for token replay from unfamiliar ASN/geography matching Vultr ranges.

1 Week

  • Deploy phishing-resistant MFA (FIDO2/passkeys) for M365 and ad-platform admins — AiTM frameworks cannot replay hardware-bound credentials.
  • Enable AWS SCPs restricting Bedrock to approved roles; turn on GuardDuty and CloudTrail anomaly alerting for LLM API usage.
  • Implement brand-lookalike domain monitoring for your org and the AI brands you use; tighten browser isolation for ad-account management roles.
  • Patch or mitigate the full CVE list (ProxyLogon, ProxyNotShell, CVE-2024-4577) — scanners bundling them with Langflow exploitation indicate any legacy exposure will be found.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.