• Beware these new phishing attacks use a convincing fake Adobe Re

    From TechnologyDaily@1337:1/100 to All on Thu Sep 10 15:15:21 2026
    Beware these new phishing attacks use a convincing fake Adobe Reader pages
    to trick victims into installing malware

    Date:
    Thu, 10 Sep 2026 14:05:00 +0000

    Description:
    Crooks are deploying cheeky browser-in-the-browser techniques to trick
    victims into downloading RMM tools.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Huntress warns of phishing campaign abusing Adobe branding with browserinthebrowser trick Victims lured into fake update pages, unknowingly installing rogue ScreenConnect clients Attackers gain persistent remote access; defenders urged to restrict RMM installs and monitor IoCs Security researchers Huntress have warned of an ongoing phishing campaign that abuses Adobe s brand while deploying clever browser-in-the-browser (BitB) techniques to trick the victims.

    The goal is to deliver rogue ScreenConnect clients which would grant the attackers persistent access to target devices. In its report , Huntress says it could not find the lure itself and thus could not report what the scam looks like. However, it saw the victims clicking on a link in the email and then being redirected to a typosquatted domain https[://]adoube[.]vu that spoofs an Adobe landing page. Latest Videos From TechRadar Watch full video here: We heard you like browsers This is where we get to the scams unique twist. Usually, phishing lures would simply redirect victims to a malicious website which could be identified simply by looking at the address bar. If
    the domain differs from the legitimate one, the scam falls apart. To work around that problem, scammers came with a solution called browser in the browser.

    Using either HTML, CSS, or JavaScript, the crooks would create an entire fake browser window, including the address bar, URL, padlock icon, and more,
    inside the actual webpage content itself. Therefore, if the victim isnt all too careful, they might look at the fake address bar, see a legitimate URL, and believe they are visiting the correct website. You may like Hackers use fake Adobe and Zoom updates to load malware onto victim devices Microsoft login pages are being abused as hackers try and lure in unlucky victims Experts flag Bank of America phishing scam that hands your device over to hackers

    In this fake browser window, the fraudsters display a blurred .PDF document. Overlaid is a message saying the documents are secured and created with the latest version of Adobe. The only way to read them, the message continues, is to update or download Adobe PDF Reader. Expectedly, there is a big View Files button just under the notification, leading to a different, equally fake BitB page, showing the download progress. In the background, something gets downloaded.

    Victims might think theyre getting a PDF reader, while in reality theyre getting a rogue version of ScreenConnect. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
    with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
    Poisoned ScreenConnect instances On its own, ScreenConnect is not malware, or dangerous in any other way. It is a legitimate remote access and support software , similar to TeamViewer, AnyDesk, or Remote Desktop, allowing IT professionals remotely connect to and control computers and other devices. These variants, however, are tainted to enable threat actors to obtain persistent remote access to their targets endpoints, Huntress explained.

    The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com. The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection, the researchers said. This initial malicious ScreenConnect Client used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect Client configured to communicate with attacker-controlled IP. Both clients established service-based persistence
    for continued remote access.

    After installation, the attackers used the second ScreenConnect session to
    run HideCursor.exe, an executable, as the name suggests, that helps the attackers hide their mouse activity. What to read next Hackers are hijacking legitimate news websites and reviews to drum up publicity HP warns hackers
    are turning popular remote access tools into dangerous, stealthy backdoors
    New malware targets Microsoft Teams users by posing as your company's IT helpdesk

    Huntress researchers dont know what the endgame is, since the threat actors were spotted and shut down in this stage of the attack. The researchers also did not share the details about the target, such as the size of the organization, or the industry it operates in. Therefore, it is impossible to even speculate on the nature of the attack and if the threat actors aimed to install ransomware.

    Still, the researchers stressed the importance of training employees to treat unexpected software update prompts and file-viewing pages with caution, and
    to make sure they know how to verify downloads through trusted channels. IT teams should also restrict who can install remote-management tools, maintain an approved inventory of RMM software, and alert on new or unapproved ScreenConnect clients, unusual relay connections, and executables launched from the user Downloads folders.

    Finally, businesses should monitor for Indicators of Compromise (IoC) listed on this page . The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/watch-out-these-new-phishing-attacks-us e-a-convincing-fake-adobe-reader-pages-to-trick-victims-into-installing-malwar e


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)