Back to Intelligence

Fake AI Ads BitB Phishing Platform + Akira Ransomware RDP Intrusion: OTX Pulse Analysis — Enterprise Detection Pack

SA
Security Arsenal Team
October 7, 2026
10 min read

Threat Summary

Two concurrent OTX pulses from 2026-10-07 paint a picture of the modern intrusion economy operating at both ends of the attack spectrum: high-fidelity social engineering for credential harvesting, and hands-on-keyboard ransomware operations for monetization.

Pulse 1 — "Behind the Connect Button": Researchers at Island uncovered a human-operated phishing platform impersonating AI advertising products for Muse, Gemini, Claude, ChatGPT, and Perplexity. The operators abuse Browser-in-the-Browser (BitB) techniques — rendering fake authentication windows inside the phishing page itself so the address bar victims inspect is itself forged. When a target clicks a "Connect" button to link their advertising account, operators harvest credentials in real time, with infrastructure suggesting MFA bypass capability (likely adversary-in-the-middle session token relay). The campaign specifically targets advertising account credentials in the Technology and Media sectors — high-value assets because ad accounts carry pre-authorized payment methods and can be resold or used for malvertising within hours of compromise. Supporting tags point to socket.io for real-time operator-victim interaction during the phish.

Pulse 2 — Akira Ransomware Intrusion: A September intrusion investigation (Huntress) documents a textbook Akira affiliate playbook: initial access via exposed/brute-forced RDP, immediate antivirus disabling on the beachhead endpoint, Rclone deployment for bulk data exfiltration, and a GOST tunnel for persistent covert C2/egress before ransomware detonation.

These pulses are not directly linked, but they represent the same kill-chain logic: steal or buy access, establish covert persistence, exfiltrate, monetize. The fake AI ads campaign is exactly the kind of initial-access factory that feeds ransomware affiliates valid corporate credentials.

Threat Actor / Malware Profile

Fake AI Ads Phishing Platform (Unknown Actor)

  • Distribution: Malvertising and social engineering lures posing as official AI platform advertising products ("Claude Ads", "Gemini Advertisers", "Manus by Meta"). Lure domains mimic legitimate product naming.
  • Payload behavior: No traditional malware payload. The phishing kit renders a BitB fake SSO/OAuth window (simulated browser chrome, fake URL bar showing legitimate domains) while the victim remains on the phishing domain. Credentials and MFA codes are relayed to human operators in real time, consistent with socket.io-based live interaction.
  • C2 communication: WebSocket (socket.io) channels between the victim's browser session and operator infrastructure for live credential/MFA interception and session hijacking.
  • Persistence: Stolen session tokens and OAuth grants provide account-level persistence independent of endpoint state; compromised ad accounts are then used for downstream malvertising or resold.
  • Anti-analysis: Operator-in-the-loop gating (human approval before serving the credential page), legitimate-looking TLS on lookalike domains, and abuse of trusted brand identity rather than exploit code — evading most signature and sandbox controls.

Akira Ransomware (S1129)

  • Distribution: Initial access via exposed RDP — password spraying, brute force, or purchased credentials.
  • Payload behavior: Double-extortion ransomware. Before encryption, the affiliate stages Rclone (rclone.exe, often renamed) configured against cloud storage (Mega, etc.) for bulk data theft.
  • C2 communication: GOST (GO Simple Tunnel) deployed to establish encrypted SOCKS5/relay tunnels, blending egress with legitimate TLS and providing resilient remote access even after RDP is cut.
  • Persistence: GOST tunnel service plus any accounts created during the intrusion; RDP left enabled as re-entry vector.
  • Anti-analysis: Antivirus/EDR disabling as the first post-access action (tampering with Defender via registry or bringing vulnerable drivers), renaming Rclone to innocuous filenames, and tunneling C2 to avoid domain-reputation detections. Observed egress IP 64.227.4.134 sits on DigitalOcean (AS14061) — cheap, disposable VPS infrastructure typical of Akira affiliates.

IOC Analysis

The two pulses contribute complementary indicator classes:

  • Domains (8 sampled of 108 total): sync-account.com, verification-security.com, payment-confirm.com, claude-ads.ai, claude-advertisers.ai, gemini-ads-team.com, gemini-advertisers.com, manusbymeta.com. Note the two naming conventions: generic trust-bait (verification-security, payment-confirm) and brand-impersonation (claude-ads.ai, manusbymeta.com). These should be blocked at DNS/proxy and used for retro-hunting in proxy, DNS, and TLS SNI logs. Also hunt for the full 108-indicator set from the OTX pulse, as operators rotate lure domains rapidly.
  • IPv4: 64.227.4.134 (DigitalOcean, US) — Akira egress/tunnel infrastructure. Block at egress and hunt netflow for any historical connections. Treat any unexpected outbound to DigitalOcean/Vultr/Linode AS space from servers as suspicious pending baseline.
  • FileHash-SHA256 (2): d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4, 1f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fba — load into EDR blocklists and hash-reputation lookups (VirusTotal, OTX, MISP). Hash indicators age fast; pair them with behavioral detections for renamed Rclone and GOST.

Operationalization: Ingest the full pulse IOC sets into your TIP (MISP/OpenCTI pulling the OTX API), push domains/IPs to DNS sinkhole and egress firewall, push hashes to EDR prevention. For the phishing domains, prioritize TLS SNI and DNS query logging since the attack never drops a file — network telemetry is your only pre-credential-theft visibility.

Detection Engineering

YAML
---
title: Browser-in-the-Browser Phishing Domain Resolution - Fake AI Ads Campaign
id: 7f3a1c2e-9b4d-4e1a-a6c8-2d5f8e0b1a01
status: experimental
description: Detects DNS queries to known Fake AI Ads campaign phishing domains impersonating AI platform advertising products (BitB credential theft)
author: Security Arsenal Threat Intelligence
references:
    - https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
date: 2026/10/08
tags:
    - attack.initial_access
    - attack.t1566
    - attack.t1557
logsource:
    category: dns
detection:
    selection:
        query|contains:
            - 'sync-account.com'
            - 'verification-security.com'
            - 'payment-confirm.com'
            - 'claude-ads.ai'
            - 'claude-advertisers.ai'
            - 'gemini-ads-team.com'
            - 'gemini-advertisers.com'
            - 'manusbymeta.com'
    condition: selection
falsepositives:
    - Threat intelligence validation lookups
level: high
---
title: Rclone Data Exfiltration Execution - Akira Ransomware TTP
id: 8a4b2d3f-0c5e-5f2b-b7d9-3e6a9f1c2b02
status: experimental
description: Detects execution of Rclone with exfiltration-oriented flags or renamed Rclone binaries, consistent with Akira ransomware affiliate data theft
date: 2026/10/08
author: Security Arsenal Threat Intelligence
references:
    - https://www.huntress.com/blog/mapping-akira-ransomware-attack
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        Image|endswith: '\rclone.exe'
        OriginalFileName: 'rclone.exe'
    selection_cmd:
        CommandLine|contains:
            - 'copy '
            - 'sync '
            - 'move '
            - '--transfers'
            - 'mega:'
            - 's3:'
    selection_hash:
        Hashes|contains:
            - 'SHA256=d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4'
            - 'SHA256=1f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fba'
    condition: (selection_img and selection_cmd) or selection_hash
falsepositives:
    - Legitimate IT use of Rclone for backup (baseline and whitelist authorized paths/accounts)
level: high
tags:
    - attack.exfiltration
    - attack.t1567.002
---
title: GOST Tunnel Execution or Akira AV Tampering
id: 9b5c3e4a-1d6f-6a3c-c8e0-4f7b0a2d3c03
status: experimental
description: Detects GOST tunneling tool execution for covert persistence and Windows Defender tampering consistent with Akira ransomware intrusions
date: 2026/10/08
author: Security Arsenal Threat Intelligence
references:
    - https://www.huntress.com/blog/mapping-akira-ransomware-attack
logsource:
    category: process_creation
    product: windows
detection:
    selection_gost:
        - Image|endswith: '\gost.exe'
        - CommandLine|contains:
            - '-L socks5://'
            - '-L=ss://'
            - 'relay+tls'
            - '-F '
    selection_av_tamper:
        CommandLine|contains:
            - 'Set-MpPreference -DisableRealtimeMonitoring $true'
            - 'DisableRealtimeMonitoring'
            - 'sc stop WinDefend'
            - 'sc config WinDefend start=disabled'
    selection_net:
        DestinationIp: '64.227.4.134'
    condition: 1 of selection_*
falsepositives:
    - Rare legitimate GOST proxy use by developers
level: critical
tags:
    - attack.command_and_control
    - attack.t1572
    - attack.defense_evasion
    - attack.t1562.001
KQL — Microsoft Sentinel / Defender
// Hunt: Fake AI Ads phishing infra + Akira exfil/tunnel behaviors
// Microsoft Sentinel / Defender XDR

// Part 1: Network connections to phishing domains or Akira egress IP
let PhishDomains = dynamic(["sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai","claude-advertisers.ai","gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com"]);
let AkiraInfra = dynamic(["64.227.4.134"]);
let NetworkHits = DeviceNetworkEvents
| where TimeGenerated > ago(30d)
| where RemoteUrl in~ (PhishDomains) or RemoteIP in (AkiraInfra)
| project TimeGenerated, DeviceName, InitiatingProcessAccountName, InitiatingProcessFileName, RemoteUrl, RemoteIP, RemotePort;

// Part 2: Rclone / GOST execution with exfil or tunnel flags
let ProcessHits = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName =~ "rclone.exe" or ProcessVersionInfoOriginalFileName =~ "rclone.exe"
   or FileName =~ "gost.exe"
   or ProcessCommandLine has_any ("--transfers", "mega:", "socks5://", "relay+tls", "DisableRealtimeMonitoring", "sc stop WinDefend")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, FolderPath;

// Part 3: RDP logons preceding suspicious process execution (Akira initial access)
let RDPHits = SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 4624 and LogonType == 10
| summarize RDPLogons=count(), SourceIPs=make_set(IpAddress) by Account, Computer, bin(TimeGenerated, 1h)
| where RDPLogons > 20 or array_length(SourceIPs) > 3;

union NetworkHits, (ProcessHits | project-rename RemoteUrl=ProcessCommandLine), (RDPHits | project-rename DeviceName=Computer)
| sort by TimeGenerated desc
PowerShell
# Security Arsenal - IOC Hunt: Fake AI Ads Phishing + Akira Ransomware Artifacts
# Run elevated on endpoints/servers. Outputs JSON findings to C:\Temp\OTX_Hunt_Results.json

$ErrorActionPreference = 'SilentlyContinue'
$findings = @()

# --- 1. Phishing domain resolution evidence (DNS client cache) ---
$phishDomains = @('sync-account.com','verification-security.com','payment-confirm.com',
  'claude-ads.ai','claude-advertisers.ai','gemini-ads-team.com','gemini-advertisers.com','manusbymeta.com')
$dnsCache = Get-DnsClientCache | Where-Object { $d = $_.Entry; $phishDomains | Where-Object { $d -like "*$_*" } }
if ($dnsCache) { $findings += [pscustomobject]@{Type='DNS_PhishDomain'; Detail=($dnsCache | Select-Object Entry,Data | ConvertTo-Json -Compress); Host=$env:COMPUTERNAME} }

# --- 2. Akira file hashes on disk (common staging paths) ---
$hashes = @('d00833318a04caa019c6f95dcb3598ad947d405010bfb2f3cbd04530a00bc3a4',
  '1f1bb322591b6d27fd2946e373d7d2efc2f4e1e66818846060d391600b600fba')
$paths = @('C:\Users','C:\ProgramData','C:\Windows\Temp','C:\Temp')
foreach ($p in $paths) {
  Get-ChildItem $p -Recurse -File -Include *.exe,*.dll -ErrorAction SilentlyContinue | ForEach-Object {
    $h = (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()
    if ($hashes -contains $h) { $findings += [pscustomobject]@{Type='Akira_HashMatch'; Detail=$_.FullName; Host=$env:COMPUTERNAME} }
  }
}

# --- 3. Rclone / GOST binaries (including renamed: match by OriginalFileName) ---
Get-ChildItem 'C:\','D:\' -Recurse -File -Include *.exe -ErrorAction SilentlyContinue | Where-Object {
  $v = $_.VersionInfo; $v.OriginalFilename -match 'rclone|gost' -or $_.Name -match '^(rclone|gost)' 
} | ForEach-Object { $findings += [pscustomobject]@{Type='Exfil_Tunnel_Binary'; Detail="$($_.FullName) | $($_.VersionInfo.OriginalFilename)"; Host=$env:COMPUTERNAME} }

# --- 4. Defender tampering artifacts ---
$mp = Get-MpPreference
if ($mp.DisableRealtimeMonitoring -eq $true) { $findings += [pscustomobject]@{Type='AV_Tamper'; Detail='RealtimeMonitoring disabled via preference'; Host=$env:COMPUTERNAME} }
$defenderSvc = Get-Service WinDefend
if ($defenderSvc.StartType -eq 'Disabled') { $findings += [pscustomobject]@{Type='AV_Tamper'; Detail='WinDefend service disabled'; Host=$env:COMPUTERNAME} }

# --- 5. Persistence: GOST/rclone as services or scheduled tasks ---
Get-CimInstance Win32_Service | Where-Object { $_.PathName -match 'gost|rclone' } | ForEach-Object {
  $findings += [pscustomobject]@{Type='Persistence_Service'; Detail="$($_.Name): $($_.PathName)"; Host=$env:COMPUTERNAME} }
Get-ScheduledTask | Where-Object { ($_.Actions.Execute + $_.Actions.Arguments) -match 'gost|rclone' } | ForEach-Object {
  $findings += [pscustomobject]@{Type='Persistence_SchTask'; Detail=$_.TaskName; Host=$env:COMPUTERNAME} }

# --- 6. Active/recent connections to Akira egress IP ---
Get-NetTCPConnection | Where-Object { $_.RemoteAddress -eq '64.227.4.134' } | ForEach-Object {
  $findings += [pscustomobject]@{Type='Network_AkiraC2'; Detail="$($_.LocalPort) -> 64.227.4.134:$($_.RemotePort) [$($_.State)] PID $($_.OwningProcess)"; Host=$env:COMPUTERNAME} }

# --- 7. RDP exposure check ---
$rdpEnabled = (Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server').fDenyTSConnections -eq 0
if ($rdpEnabled) { $findings += [pscustomobject]@{Type='RDP_Exposure'; Detail='RDP enabled - verify NLA, MFA, and network restriction'; Host=$env:COMPUTERNAME} }

New-Item -ItemType Directory -Path 'C:\Temp' -Force | Out-Null
$findings | ConvertTo-Json -Depth 4 | Out-File 'C:\Temp\OTX_Hunt_Results.json'
Write-Host "[+] Hunt complete. $($findings.Count) findings -> C:\Temp\OTX_Hunt_Results.json"

Response Priorities

Immediate (0-4h):

  • Block all 108 phishing domains at DNS resolver, secure web gateway, and TLS SNI inspection; block 64.227.4.134 at egress and add both SHA256 hashes to EDR prevention.
  • Run the KQL query and PowerShell hunt across the estate; any Rclone/GOST binary outside an approved IT manifest is a sev-1 incident — assume pre-encryption staging.
  • Alert on any WebSocket (socket.io) sessions to newly registered domains — the phishing platform's live-operator channel.

24 hours:

  • If any user resolved a phishing domain, treat their credentials as compromised even with MFA — the BitB platform bypasses MFA via session-token relay. Force password reset, revoke all active sessions and OAuth grants for advertising, cloud, and IdP accounts, and audit ad-platform login history for anomalous OAuth authorizations.
  • Audit advertising accounts (Google Ads, Meta, LinkedIn) for unauthorized spend, new payment methods, or injected campaigns — compromised ad accounts are monetized within hours.
  • Verify Defender/EDR tamper protection is enabled fleet-wide; Akira's first move is killing AV.

1 week:

  • Eliminate internet-exposed RDP entirely — move to VPN/ZTNA with MFA and device compliance, or disable it. Akira's initial access here was RDP; this is non-negotiable hardening.
  • Deploy application control (WDAC/AppLocker) rules blocking unauthorized rclone.exe/gost.exe execution and flag any process with OriginalFileName mismatches.
  • Roll out BitB-resistant phishing awareness and technical controls: FIDO2/passkeys for ad platforms and IdP (phishing-resistant by design, defeats AiTM relay), plus conditional access policies binding sessions to device and IP.
  • Baseline egress to consumer VPS providers (DigitalOcean AS14061, Vultr, Linode) and alert on server-originated connections to unapproved cloud storage APIs.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.