Intelligence Category: Infostealer & Credential Theft Campaigns Pulse Count: 4 | TLP: WHITE | Confidence: High (multi-source corroboration: Unit42, F5 Labs, Island, Datadog Security Labs)
Threat Summary
Four concurrent OTX pulses paint a single strategic picture: identity and credential material is the primary monetization and access vector across both state-aligned and criminally-motivated operations in Q4 2026.
-
CL-STA-1178 (Blinder Tunnel) — An Iranian state-aligned actor is impersonating the Dubai Airports IT department, delivering trojanized coding challenges (fake technical assessments) to targets in Iraqi energy and government sectors, with secondary targeting of Israel. Active since November 2025, intensifying March 2026. The chain uses AppDomainManager hijacking and DLL sideloading to stage ShelbyLoader V2, which deploys RuntimeBroker.dll, PsProxy.dll, and Blackwood.dll, ultimately establishing tunneling via Chisel with GitHub abused as C2 infrastructure.
-
Langflow AI Platform Exploitation — F5 Labs observed 405 exploitation attempts from 55 distinct IPs against CVE-2026-0768, an unauthenticated RCE in the Langflow AI application-building platform. This is the first observed opportunistic internet-wide scanning against an AI/ML development platform — a milestone indicating AI dev tooling is now a commodity target for credential harvesting and initial access.
-
Fake AI Ads (Browser-in-the-Browser) — A human-operated phishing platform impersonates advertising products for Muse, Gemini, Claude, ChatGPT, and Perplexity. The Browser-in-the-Browser (BitB) technique renders fake authentication windows inside phishing pages, and operators intercept sessions in real time over Socket.IO — enabling MFA bypass and theft of enterprise advertising/cloud accounts (108 indicators).
-
AWS Bedrock Token-Jacking — Datadog identified credential-harvesting platforms (including KMON_NOC) that validate stolen AWS keys via
GetCallerIdentity, then probe Amazon Bedrock access withListFoundationModelsandConversecalls. Stolen keys are being specifically triaged for LLM access — for cryptomining-adjacent abuse, data extraction, and resale of "AI-capable" cloud accounts.
Collective objective: Harvest, validate, and weaponize credentials — human identities (BitB phishing), developer identities (trojanized coding challenges), and machine identities (AWS keys) — with AI platforms both the lure and the target.
Threat Actor / Malware Profile
CL-STA-1178 — ShelbyLoader V2 / Blinder Tunnel
- Distribution: Spear-phishing impersonating Dubai Airports IT; trojanized coding challenge archives delivered to developers/IT staff at energy and government entities.
- Payload behavior: Multi-stage chain. Initial loader executes a legitimate-signed binary that sideloads malicious DLLs (RuntimeBroker.dll, PsProxy.dll, Blackwood.dll). ShelbyLoader V2 orchestrates staged decryption and reflective loading.
- Persistence & execution hijack: AppDomainManager hijacking — malicious .NET configuration forces arbitrary CLR applications to load attacker-controlled assemblies, providing both persistence and defense evasion (every .NET app launch re-executes the payload).
- C2: Chisel tunnel (HTTP/SSH-over-HTTP) for covert RDP/SOCKS access; GitHub abused as dead-drop/C2 relay, blending with legitimate developer traffic — a deliberate choice given the developer-targeting lure.
- Anti-analysis: Staged DLL sideloading under trusted process names, legitimate cloud service C2, and in-memory-only final payloads.
Fake AI Ads Platform (BitB)
- Distribution: Malvertising and direct lures posing as AI ad-management products.
- Payload behavior: JavaScript-rendered fake OAuth/login windows (BitB) hosted on lookalike domains (
claude-ads.ai,gemini-advertisers.com,sync-account.com,payment-confirm.com). - C2 / session theft: Real-time Socket.IO channel relays entered credentials and MFA tokens/session cookies to live operators, who replay sessions immediately — defeating TOTP-based MFA.
AWS Key Validators (KMON_NOC et al.)
- Behavior: Automated validation pipeline:
sts:GetCallerIdentity(is the key alive?) →bedrock:ListFoundationModels/bedrock:Converse(is it AI-capable?) → keys triaged and resold/abused by capability tier. - Infrastructure: Distributed validation from residential/hosting IPs (e.g., 112.78.151.90, 78.109.78.211, 103.160.185.100), consistent with proxy-rotated checker platforms.
IOC Analysis
| Type | Pulses | Operationalization |
|---|---|---|
| IPv4 | CL-STA-1178 C2 (87.248.129.239); Bedrock validators (112.78.151.90, 78.109.78.211, 83.194.172.248, 103.160.185.100, 109.146.93.39, 115.138.247.83) | Block at egress proxy/firewall; retro-hunt netflow and DNS logs 90 days. Validator IPs are transient — prioritize behavior over IP blocklists. |
| Domains (108) | Fake AI Ads platform (claude-ads.ai, claude-advertisers.ai, gemini-ads-team.com, gemini-advertisers.com, manusbymeta.com, sync-account.com, verification-security.com, payment-confirm.com) | DNS sinkhole + email gateway URL rewrite block. Add brand-keywords-in-lookalike-domain detection (e.g., regex on `claude |
| SHA256 (14+) | ShelbyLoader V2 stages, sideloaded DLLs, validator tooling | Push to EDR blocklists; sweep via hash hunt across all endpoints and email attachments. |
| CVEs | CVE-2026-0768 (Langflow), CVE-2017-9841, CVE-2018-20062, CVE-2021-26855, CVE-2021-34523, CVE-2022-41082, CVE-2024-4577 | The legacy CVE set indicates bulk scanning tooling — patch verification for Exchange (ProxyLogon/ProxyShell-adjacent), PHPUnit, ThinkPHP, and PHP-CGI remains mandatory. Inventory any exposed Langflow/AI-dev instances immediately. |
Tooling: Enrich IOCs in OTX/ThreatConnect/MISP; decode AppDomainManager configs with any .NET decompiler (dnSpy/ILSpy); analyze Chisel traffic with Zeek (long-lived HTTP CONNECT / websocket upgrade patterns); validate domain infrastructure with urlscan.io and passive DNS.
Detection Engineering
Sigma Rules
---
title: AppDomainManager Hijacking - Malicious .NET Configuration (CL-STA-1178 / ShelbyLoader V2)
id: 8f3a1c2e-1178-4b7a-9c1d-blinder00001
status: experimental
description: Detects creation or modification of .NET application configuration files specifying a custom AppDomainManager assembly, a persistence and defense-evasion technique used by CL-STA-1178 ShelbyLoader V2.
author: Security Arsenal Threat Intel
date: 2026/10/07
references:
- https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/
logsource:
category: file_event
product: windows
detection:
selection_ext:
TargetFilename|endswith: '.config'
selection_content:
TargetFilename|contains:
- '\AppData\'
- '\ProgramData\'
- '\Users\Public\'
filter_legit_paths:
TargetFilename|contains:
- '\Program Files\'
- '\Windows\Microsoft.NET\'
condition: selection_ext and selection_content and not filter_legit_paths
falsepositives:
- Legitimate .NET application deployments writing config files to user profiles
level: high
tags:
- attack.persistence
- attack.defense_evasion
- attack.t1574
---
title: DLL Sideloading of RuntimeBroker or Proxy-Themed Payload DLLs
id: 8f3a1c2e-1178-4b7a-9c1d-blinder00002
status: experimental
description: Detects image loads of RuntimeBroker.dll, PsProxy.dll, or Blackwood.dll from non-system paths, matching CL-STA-1178 staged sideloading behavior.
author: Security Arsenal Threat Intel
date: 2026/10/07
logsource:
category: image_load
product: windows
detection:
selection_dll:
ImageLoaded|endswith:
- '\RuntimeBroker.dll'
- '\PsProxy.dll'
- '\Blackwood.dll'
filter_system:
ImageLoaded|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
condition: selection_dll and not filter_system
falsepositives:
- Rare third-party software shipping same-named DLLs
level: critical
tags:
- attack.defense_evasion
- attack.t1574.002
---
title: Chisel Tunnel Execution or GitHub-Based Covert C2 Indicator
id: 8f3a1c2e-1178-4b7a-9c1d-blinder00003
status: experimental
description: Detects Chisel tunneling client/server execution via command-line artifacts (client/server modes, socks, reverse flags) associated with Blinder Tunnel campaign covert channels.
author: Security Arsenal Threat Intel
date: 2026/10/07
logsource:
category: process_creation
product: windows
detection:
selection_cli:
CommandLine|contains:
- ' client '
- ' server '
selection_flags:
CommandLine|contains:
- 'R:socks'
- '--socks5'
- '--reverse'
- ':socks'
selection_img:
Image|endswith:
- '\chisel.exe'
- '\chisel'
condition: (selection_cli and selection_flags) or selection_img
falsepositives:
- Legitimate penetration testing or red team activity using Chisel
level: high
tags:
- attack.command_and_control
- attack.t1572
- attack.t1090
KQL (Microsoft Sentinel)
// Hunt: CL-STA-1178 IOCs, Fake AI Ads BitB domains, and AWS Bedrock validator infrastructure
let C2_IPs = dynamic(["87.248.129.239","112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83"]);
let PhishDomains = dynamic(["sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai","claude-advertisers.ai","gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com"]);
let MalHashes = dynamic(["6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239","f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9","53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402","923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608","c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc"]);
let NetworkHits = DeviceNetworkEvents
| where RemoteIP in (C2_IPs) or RemoteUrl has_any (PhishDomains)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort, ActionType;
let HashHits = DeviceProcessEvents
| where SHA256 in (MalHashes)
| project TimeGenerated, DeviceName, FileName, FolderPath, SHA256, ProcessCommandLine, AccountName;
let SideloadHits = DeviceImageLoadEvents
| where FileName in~ ("RuntimeBroker.dll","PsProxy.dll","Blackwood.dll")
| where FolderPath !startswith "C:\\Windows\\System32" and FolderPath !startswith "C:\\Windows\\SysWOW64"
| project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine;
union NetworkHits, HashHits, SideloadHits
| sort by TimeGenerated desc
PowerShell IOC Hunt Script
# Security Arsenal — CL-STA-1178 / BitB Phishing / Bedrock Validator Hunt
# Run elevated. Checks network IOCs, AppDomainManager hijack artifacts, sideloaded DLLs, and phishing DNS cache.
$C2IPs = @("87.248.129.239","112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83")
$PhishDomains = @("sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai","claude-advertisers.ai","gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com")
$SideloadDlls = @("RuntimeBroker.dll","PsProxy.dll","Blackwood.dll")
$MalHashes = @("6e7d9b33f1e72ea1ede71373a604ecdb060dab7d42055179c1eede9ecd1fd239","f5b12772db6817f7a765a6fe7565fd3d4f87edc28e42fe3ec0244a372a410fc9","53f35e49eb9b271fd8cbcd3daacb525328dbf159a03dbd1c7adebe0363daa402","3fd810a3aa0039993393741b32287c367a9a5037a41e826906440887cdd3ed13","76273382e4252c1f60a2251141e108942494409c759358320735891762c0682e","d3561bd4aad003dc3e08157b0891860bb496b80cd6e44901692e08ab1d4e8260","f5ba1645694c62f527ed6ceda8c68a5c3dd92b4032439167e8e937e72803b4bd","923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608","c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc")
Write-Host "=== [1] Active network connections to C2/validator IPs ==="
Get-NetTCPConnection | Where-Object { $C2IPs -contains $_.RemoteAddress } |
Select-Object LocalPort, RemoteAddress, RemotePort, State, OwningProcess,
@{N='Process';E={(Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).ProcessName}} | Format-Table -AutoSize
Write-Host "=== [2] DNS cache hits for BitB phishing domains ==="
Get-DnsClientCache | Where-Object { $d = $_.Entry; $PhishDomains | Where-Object { $d -like "*$_*" } } | Format-Table -AutoSize
Write-Host "=== [3] AppDomainManager hijack artifacts (.config files referencing custom AppDomainManager) ==="
$paths = @("$env:APPDATA","$env:LOCALAPPDATA","C:\ProgramData","C:\Users\Public")
foreach ($p in $paths) {
Get-ChildItem -Path $p -Recurse -Filter "*.config" -ErrorAction SilentlyContinue |
Where-Object { (Get-Content $_.FullName -Raw -ErrorAction SilentlyContinue) -match "AppDomainManager" } |
Select-Object FullName, LastWriteTime
}
Write-Host "=== [4] Sideloaded DLLs outside System32/SysWOW64 ==="
foreach ($dll in $SideloadDlls) {
Get-ChildItem -Path "C:\Users","C:\ProgramData" -Recurse -Filter $dll -ErrorAction SilentlyContinue |
Select-Object FullName, Length, LastWriteTime
}
Write-Host "=== [5] Hash sweep of common staging directories ==="
foreach ($p in $paths) {
Get-ChildItem -Path $p -Recurse -Include *.dll,*.exe -ErrorAction SilentlyContinue | ForEach-Object {
$h = (Get-FileHash $_.FullName -Algorithm SHA256 -ErrorAction SilentlyContinue).Hash
if ($MalHashes -contains $h.ToLower()) { Write-Host "[!] MALICIOUS HASH: $($_.FullName)" -ForegroundColor Red }
}
}
Write-Host "=== [6] Suspicious Chisel processes ==="
Get-CimInstance Win32_Process | Where-Object { $_.CommandLine -match "R:socks|--socks5|--reverse|chisel" } |
Select-Object ProcessId, Name, CommandLine | Format-List
Write-Host "=== Hunt complete. Review hits and escalate per IR runbook. ==="
Response Priorities
Immediate (0–4 hours)
- Block all listed C2/validator IPv4s and the 108 BitB phishing domains at egress proxy, DNS, and email gateway.
- Push the 14+ SHA256 hashes to EDR blocklists; run the PowerShell hunt script on endpoints in energy/government segments and developer workstations (coding-challenge lure targets IT staff specifically).
- Hunt for AppDomainManager config artifacts and Chisel command lines using the Sigma rules and KQL above.
- Verify no internet-exposed Langflow or AI-dev platform instances exist; if found, take offline or patch CVE-2026-0768 immediately.
24 Hours
- Credential-stealing malware is confirmed across all four pulses — treat any host with IOC hits as fully compromised for identity:
- Force password + MFA reset for all users of affected endpoints; revoke all active sessions/OAuth grants (the BitB campaign steals live session cookies — password reset alone is insufficient).
- Rotate every AWS access key; audit CloudTrail for
GetCallerIdentity→ListFoundationModels/Conversesequences from unfamiliar IPs (KMON_NOC validation pattern); enforce SCPs restricting Bedrock to approved principals. - Review advertising platform accounts (Google/Meta/AI ad consoles) for unauthorized sessions and new admin users.
1 Week
- Deploy the Sigma detections to production SIEM with tuned thresholds; add Zeek detection for Chisel-style long-lived HTTP tunnels and GitHub C2 beaconing anomalies.
- Implement phishing-resistant MFA (FIDO2/passkeys) for advertising, cloud console, and developer tooling accounts — TOTP is defeated by the Socket.IO real-time relay.
- Harden .NET attack surface: enable WDAC/AppLocker policies blocking unsigned assemblies loading from user-writable paths; alert on
.configmodifications outside deployment pipelines. - Move AWS workloads to short-lived credentials (IAM Roles/SSO); eliminate long-lived access keys where feasible, and add Bedrock API anomaly alerts.
- Brief developers on the trojanized-coding-assessment lure — any unsolicited "technical challenge" from an airport/logistics IT department is a CL-STA-1178 indicator.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.