Huntress warns of Adobe-branded phishing campaign installing rogue ScreenConnect clients
Huntress researchers say an active phishing campaign spoofs Adobe with a browser-in-the-browser fake update page, then installs rogue ScreenConnect clients that give attackers persistent remote access.
Huntress said in its report that it could not find the lure email itself and therefore could not describe what the scam message looks like. What the researchers did observe was victims clicking a link in an email and being redirected to a typosquatted domain, https[:]//adoube[.]vu, that spoofs an Adobe landing page.
The campaign's distinguishing feature is the browser-in-the-browser, or BitB, trick. Ordinarily a phishing page can be spotted by checking the address bar, because a domain that differs from the legitimate one exposes the scam. Using HTML, CSS or JavaScript, the attackers build an entire fake browser window inside the actual web page, complete with address bar, URL and padlock icon. A victim who does not look closely can read the fake address bar, see a plausible URL and conclude that the site is genuine.
Inside that fake window, the fraudsters display a blurred .PDF document. An overlaid message states that the documents are "secured" and were created with "the latest version of Adobe," and says the only way to read them is to "update or download Adobe PDF Reader." A large "View Files" button sits beneath the notification and leads to a second, equally fake BitB page that shows a download progress bar while something is downloaded in the background. Victims may believe they are getting a PDF reader; Huntress says they are in fact getting a rogue version of ScreenConnect.
ScreenConnect itself is legitimate remote access and support software, comparable to TeamViewer, AnyDesk or Remote Desktop, and is used by IT professionals to connect to and control computers and other devices. The variants deployed in this campaign are modified so that threat actors can obtain persistent remote access to target endpoints, according to Huntress.
The researchers described the sequence in their report. "The first initial remote client installed was the rogue ScreenConnect Client configured to communicate with instance-uxh86b-relay[.]screenconnect[.]com," they wrote. "The attacker used a legitimate ScreenConnect Trial Relay domain to further avoid detection." That first client, they added, used the native Windows command shell and curl to retrieve and install a second malicious ScreenConnect client configured to communicate with an attacker-controlled IP address. Both clients established service-based persistence for continued remote access.
After installation, the attackers used the second ScreenConnect session to run HideCursor.exe, an executable whose purpose, as its name suggests, is to conceal the attackers' mouse activity. Huntress said it does not know what the endgame was, because the threat actors were detected and shut down at this stage of the attack. The researchers also did not disclose details about the target, such as the size of the organization or the industry it operates in, which makes it impossible to assess whether the ultimate aim was, for example, the deployment of ransomware.
Huntress stressed that employees should be trained to treat unexpected software update prompts and file-viewing pages with caution, and to verify downloads through trusted channels. IT teams should restrict who is permitted to install remote management tools, keep an approved inventory of RMM software, and generate alerts for new or unapproved ScreenConnect clients, unusual relay connections and executables launched from users' Downloads folders. The researchers also advised businesses to monitor for the indicators of compromise listed in their report.