Beware — these new phishing attacks use a convincing fake Adobe Reader pages to trick victims into installing malware
Crooks are deploying cheeky browser-in-the-browser techniques to trick victims into downloading RMM tools.
Security researchers Huntress have issued a warning about an ongoing phishing campaign that utilizes Adobe's branding and browser-in-the-browser (BitB) techniques to trick victims. The goal is to install rogue ScreenConnect clients, which grant attackers persistent remote access to target devices. Huntress could not identify the lure but detected victims clicking on a link leading to the typosquatted domain https://adoube.vu, which mimics an Adobe landing page.
To avoid detection, scammers created a fake browser window within the email content, displaying a blurred PDF document titled as "secured" with "the latest version of Adobe." The message instructs victims to update or download Adobe PDF Reader, which leads to the download of a rogue ScreenConnect client. ScreenConnect is a legitimate remote access software, but in this case, it has been compromised to enable threat actors' persistent access to the victim's device.
The first installed client communicates with a relay server, and a second client retrieves and installs additional malicious ScreenConnect instances for further access. The attackers then used the second ScreenConnect session to run HideCursor.exe, which helps conceal their mouse activity. While the endgame remains unclear, Huntress emphasizes the importance of training employees to avoid unexpected software update prompts and file-viewing pages, verifying downloads through trusted channels, restricting remote-management tool installations, monitoring for unusual relay connections, and alerting on new or unapproved ScreenConnect clients.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.