Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Phishing campaign uses fake Adobe page to deliver rogue ScreenConnect

Security researchers at Huntress have warned of an ongoing phishing campaign that abuses Adobe’s brand to deliver rogue ScreenConnect clients. The campaign uses a browser-in-the-browser (BitB) technique to make a malicious page appear legitimate.

Victims clicked a link in an email and were redirected to the typosquatted domain adoube.vu, which imitated an Adobe landing page. Huntress said it could not obtain the original lure. The fake page displayed a browser window inside the real webpage, including an address bar, URL, and padlock icon.

Inside that window, attackers showed a blurred PDF and a message claiming the document was secured and created with the latest version of Adobe. The message told visitors to update or download Adobe PDF Reader. A View Files button led to another fake BitB page that displayed download progress.

The download appeared to be a PDF reader but was actually a rogue ScreenConnect client. ScreenConnect is legitimate remote-access and support software, similar to TeamViewer, AnyDesk, and Remote Desktop. The altered clients enabled persistent remote access. Huntress said an initial client communicated with a legitimate ScreenConnect Trial Relay domain, while another used a domain controlled by the attackers. Both established service-based persistence.

The attackers then used the remote session to run HideCursor.exe, which can hide mouse activity. Huntress researchers said the campaign was detected and stopped at that stage, leaving its ultimate objective unknown.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.