Back to Intelligence

Fake AI Ads Browser-in-the-Browser + AWS Bedrock Token-Jacking: OTX Pulse Detection Pack

SA
Security Arsenal Team
October 7, 2026
8 min read

The two OTX pulses describe a converging credential-theft problem rather than a single named intrusion set. The first campaign uses social-engineered ads impersonating AI products such as Muse, Gemini, Claude, ChatGPT, and Perplexity, then presents a fake Connect flow through Browser-in-the-Browser windows. The objective is to steal advertising, platform, and likely SSO-linked credentials while bypassing user suspicion and weak MFA controls. Infrastructure observed includes phishing domains such as sync-account.com, verification-security.com, payment-confirm.com, claude-ads.ai, claude-advertisers.ai, gemini-ads-team.com, gemini-advertisers.com, and manusbymeta.com.

The second pulse shows the cloud-side monetization and validation path: actors harvest exposed AWS keys, validate them with GetCallerIdentity, and then test Amazon Bedrock access with ListFoundationModels and related read-only calls. Datadog researchers link this behavior to credential-validation platforms including KMON_NOC. The practical enterprise risk is a chain: phished SaaS or ad-platform credentials create access and payment fraud; leaked or stolen AWS keys are rapidly triaged for LLM access, data exposure, cost abuse, and downstream identity pivoting.

MITRE ATT&CK fields are not consistently enriched in the pulses, so detection should focus on observed behaviors: phishing-domain resolution, browser-initiated deceptive authentication windows, AWS credential validation, Bedrock model enumeration, and anomalous use of valid credentials from unusual networks.

Threat Actor / Malware Profile

No named malware family or mature APT actor is attributed in the pulses. The activity is best profiled as human-operated credential phishing plus cloud credential validation tooling.

Distribution method: malicious or compromised advertising and search/social lures impersonate AI brands and advertiser-support workflows. Victims are pushed toward lookalike domains with security-, payment-, verification-, and advertiser-themed names.

Payload behavior: the fake Connect button launches a Browser-in-the-Browser authentication window that visually imitates an OAuth or SSO prompt while remaining on attacker infrastructure. Socket.IO tags suggest interactive session control, relay, or operator-assisted capture. AWS-side tooling performs lightweight validation before committing to abuse: STS GetCallerIdentity to confirm key validity, then Bedrock ListFoundationModels or similar calls to determine whether LLM access is enabled.

C2 communication: for the phishing kit, expect HTTPS to attacker domains and websocket or Socket.IO-like channels for live operator interaction. For AWS validation, the relevant C2 is legitimate AWS API endpoints contacted from attacker IP space, including 112.78.151.90, 78.109.78.211, 83.194.172.248, 103.160.185.100, 109.146.93.39, and 115.138.247.83 in the supplied sample.

Persistence mechanism: phishing kits usually do not persist on endpoints; persistence is achieved through stolen sessions, OAuth grants, ad-account roles, mailbox rules, or newly created cloud access keys. In AWS, persistence may appear as new IAM users, access keys, login profiles, role trust changes, or Bedrock model invocation logging gaps.

Anti-analysis techniques: lookalike domains, brand impersonation, short-lived infrastructure, cloaking by geography or user agent, fake modal windows that defeat casual URL inspection, use of valid AWS APIs to blend into normal cloud control-plane traffic, and read-only enumeration designed to avoid obvious destructive alerts.

IOC Analysis

The indicator set contains three operational classes. Domains are highest value for web proxy, DNS sinkhole, SWG, EDR network telemetry, and email/security gateway controls. IPv4 addresses are useful for cloud-control-plane alerting, egress firewall review, and threat-intel enrichment, but should be treated as time-sensitive because cloud validation nodes rotate quickly. SHA256 values are most useful for retro-hunts across EDR file telemetry, email attachments, download caches, and malware detonation stores even when no family name is assigned.

SOC teams should operationalize indicators by confidence and aging: block the phishing domains immediately at DNS and proxy; alert rather than silently block on AWS API calls unless correlated with known-bad IPs, impossible travel, new credentials, or disabled logging; load hashes into EDR and sandbox retro-search; and add all indicators to a watchlist with expiry dates. Useful tooling includes EDR network/file telemetry, DNS resolver logs, Microsoft Defender XDR or Sentinel, Zeek/Suricata for proxy egress, CloudTrail Lake or SIEM queries for AWS, YARA for file triage, and jq or Python for indicator normalization.

Detection Engineering

YAML
---
title: Fake AI Advertising Phishing Domain Resolution
id: 6f1b7f19-7d8d-4a52-9a1f-fakeaiads001
status: experimental
description: Detects DNS or proxy lookups for fake AI advertising and credential-verification domains observed in OTX pulse Behind the Connect Button.
references:
  - https://www.island.io/blog/behind-the-connect-button-the-fake-ai-ads-campaign
author: Security Arsenal Detection Engineering
date: 2026/10/08
logsource:
  category: dns
product: windows
level: high
tags:
  - attack.phishing
  - attack.t1566
  - attack.t1071.001
detection:
  selection:
    query|contains:
      - sync-account.com
      - verification-security.com
      - payment-confirm.com
      - claude-ads.ai
      - claude-advertisers.ai
      - gemini-ads-team.com
      - gemini-advertisers.com
      - manusbymeta.com
  condition: selection
falsepositives:
  - Rare brand-safety or researcher detonation traffic
fields:
  - Image
  - QueryName
  - QueryResults
  - Computer
---
title: AWS Credential Validation Followed By Bedrock Enumeration
id: 3b68a2a2-8d36-4f2d-9f2b-awsbedrock002
status: experimental
description: Detects suspicious AWS control-plane sequence where STS GetCallerIdentity is followed by Amazon Bedrock ListFoundationModels from uncommon networks.
references:
  - https://securitylabs.datadoghq.com/articles/beyond-valid-credentials-how-exposed-aws-keys-are-tested-for-amazon-bedrock-access
author: Security Arsenal Detection Engineering
date: 2026/10/08
logsource:
  product: aws
  service: cloudtrail
level: high
tags:
  - attack.valid_accounts
  - attack.t1078
  - attack.t1526
detection:
  selection_identity:
    eventSource: sts.amazonaws.com
    eventName: GetCallerIdentity
  selection_bedrock:
    eventSource: bedrock.amazonaws.com
    eventName:
      - ListFoundationModels
      - ListModelCustomizationJobs
      - GetFoundationModel
  timeframe: 10m
  condition: selection_identity and selection_bedrock
falsepositives:
  - Developers validating new IAM roles or Bedrock onboarding
fields:
  - awsRegion
  - sourceIPAddress
  - userIdentity.principalId
  - userAgent
  - eventName
---
title: Suspicious Browser Or Script Process Connecting To Credential Phishing Infrastructure
id: 9a94cbe5-332e-4f1d-9f42-bitb003
status: experimental
description: Detects browsers, Electron-style apps, or script hosts making network connections to fake AI ad phishing domains or observed validation IPs.
author: Security Arsenal Detection Engineering
date: 2026/10/08
logsource:
  category: network_connection
  product: windows
level: high
tags:
  - attack.command_and_control
  - attack.phishing
  - attack.t1071.001
detection:
  selection_proc:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\brave.exe'
      - '\electron.exe'
      - '\node.exe'
      - '\powershell.exe'
      - '\wscript.exe'
      - '\cscript.exe'
  selection_net:
    DestinationHostname|contains:
      - sync-account.com
      - verification-security.com
      - payment-confirm.com
      - claude-ads.ai
      - claude-advertisers.ai
      - gemini-ads-team.com
      - gemini-advertisers.com
      - manusbymeta.com
    DestinationIp:
      - 112.78.151.90
      - 78.109.78.211
      - 83.194.172.248
      - 103.160.185.100
      - 109.146.93.39
      - 115.138.247.83
  condition: selection_proc and selection_net
falsepositives:
  - Threat research, sandbox detonation, or vendor validation
fields:
  - Image
  - CommandLine
  - DestinationHostname
  - DestinationIp
  - User
KQL — Microsoft Sentinel / Defender
let phishing_domains = dynamic(["sync-account.com","verification-security.com","payment-confirm.com","claude-ads.ai","claude-advertisers.ai","gemini-ads-team.com","gemini-advertisers.com","manusbymeta.com"]);
let validation_ips = dynamic(["112.78.151.90","78.109.78.211","83.194.172.248","103.160.185.100","109.146.93.39","115.138.247.83"]);
let hashes = dynamic(["923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608","c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc"]);
let endpoint_net = DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where RemoteUrl has_any (phishing_domains) or RemoteIP in (validation_ips)
| project EndpointSignal="DeviceNetworkEvents", TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, RemotePort, ActionType;
let endpoint_proc = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where FileName in~ ("chrome.exe","msedge.exe","firefox.exe","brave.exe","node.exe","powershell.exe","wscript.exe","cscript.exe")
| where ProcessCommandLine has_any (phishing_domains) or SHA256 in (hashes)
| project EndpointSignal="DeviceProcessEvents", TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName;
let aws_control = CloudTrailEvents
| where TimeGenerated > ago(14d)
| where SourceIP in (validation_ips) or (EventSource has "sts.amazonaws.com" and EventName == "GetCallerIdentity") or (EventSource has "bedrock.amazonaws.com" and EventName in ("ListFoundationModels","GetFoundationModel","ListModelCustomizationJobs"))
| project EndpointSignal="CloudTrail", TimeGenerated, SourceIP, UserIdentityPrincipalId, UserAgent, EventSource, EventName, AWSRegion, ErrorCode;
union endpoint_net, endpoint_proc, aws_control
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Signals=make_set(EndpointSignal), Hosts=make_set(DeviceName), IPs=make_set(RemoteIP), Users=make_set(AccountName), AwsPrincipals=make_set(UserIdentityPrincipalId) by EndpointSignal, RemoteUrl, RemoteIP, FileName, EventName
| sort by LastSeen desc
PowerShell
$ErrorActionPreference = 'SilentlyContinue'
$domains = @('sync-account.com','verification-security.com','payment-confirm.com','claude-ads.ai','claude-advertisers.ai','gemini-ads-team.com','gemini-advertisers.com','manusbymeta.com')
$ips = @('112.78.151.90','78.109.78.211','83.194.172.248','103.160.185.100','109.146.93.39','115.138.247.83')
$hashes = @('923641364ef0ce3a6f1d944890244082b8c7f29c9600c0433b2a0ca9822c0608','c9335bb8a21bd2c568d03b040fb86a0e72145691e54a33495ee0cfaac55835dc')

Write-Output '[DNS cache hits]'
Get-DnsClientCache | Where-Object { $n=$_.Entry; $domains | ForEach-Object { $n -like ('*' + $_ + '*') } } | Select-Object Entry, Data, TimeToLive

Write-Output '[Active TCP connections to validation IPs]'
Get-NetTCPConnection | Where-Object { $ips -contains $_.RemoteAddress } | Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess

Write-Output '[Hosts file overrides]'
$hosts = Get-Content "$env:windir\System32\drivers\etc\hosts"
foreach ($line in $hosts) { foreach ($d in $domains) { if ($line -like ('*' + $d + '*')) { $line } } }

Write-Output '[AWS credential artifacts]'
$awsPaths = @("$env:USERPROFILE\.aws\credentials","$env:USERPROFILE\.aws\config","$env:ProgramData\Amazon")
foreach ($p in $awsPaths) { if (Test-Path $p) { Get-Item $p | Select-Object FullName, LastWriteTime } }
Get-ChildItem Env: | Where-Object { $_.Name -match 'AWS_ACCESS_KEY_ID|AWS_SECRET_ACCESS_KEY|AWS_SESSION_TOKEN|AWS_PROFILE' } | Select-Object Name

Write-Output '[Recent executable hash match in user-writable paths]'
$scanRoots = @("$env:TEMP","$env:LOCALAPPDATA\Temp","$env:USERPROFILE\Downloads","$env:USERPROFILE\AppData\Local\Microsoft\Windows\INetCache")
foreach ($root in $scanRoots) {
  if (Test-Path $root) {
    Get-ChildItem $root -Recurse -File -Include *.exe,*.dll,*.js,*.ps1,*.msi -ErrorAction SilentlyContinue |
      Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-14) } |
      ForEach-Object { $h = Get-FileHash $_.FullName -Algorithm SHA256; if ($hashes -contains $h.Hash) { [pscustomobject]@{Path=$_.FullName; Hash=$h.Hash; LastWriteTime=$_.LastWriteTime} } }
  }
}

Write-Output '[Suspicious browser extensions and scheduled tasks referencing lure themes]'
Get-ScheduledTask | Where-Object { $_.TaskName -match 'claude|gemini|chatgpt|perplexity|advertis|payment|verify' -or ($_.Actions.Execute + ' ' + $_.Actions.Arguments) -match 'claude|gemini|chatgpt|perplexity|payment|verify' } | Select-Object TaskName, TaskPath, State

Response Priorities

Immediate: block and sinkhole the listed domains at DNS, secure web gateway, email gateway, and EDR network controls; add the IPv4 addresses and hashes to watchlists; search 14 days of endpoint network telemetry and CloudTrail for GetCallerIdentity plus Bedrock enumeration; identify users who clicked AI advertising Connect prompts; revoke exposed AWS keys and invalidate active web sessions; check ad platforms and identity providers for new OAuth grants, mailbox rules, payment changes, and MFA resets.

24h: force credential resets for impacted users and administrators; revoke refresh tokens, app passwords, OAuth consents, API tokens, and AWS sessions tied to affected principals; review CloudTrail for new access keys, IAM users, role trust edits, Bedrock model invocation, Cost Explorer spikes, and GuardDuty findings; verify MFA number matching or phishing-resistant MFA for high-risk users; capture phishing pages safely for kit reconstruction and extract websocket endpoints.

1 week: harden architecture by enforcing phishing-resistant MFA, restricting OAuth consent, adding browser isolation for ad-tech and brand-impersonation categories, enabling DNS protective controls, alerting on GetCallerIdentity from non-corporate ASN ranges, requiring IMDSv2, removing long-lived access keys in favor of roles, enabling Bedrock invocation logging and budget anomaly alerts, and adding brand-impersonation monitoring for AI product names.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.