Security/ phishing · adobe · screenconnect · malware

Fake Adobe Update Page Tricks Victims Into Remote Access Malware

A phishing campaign spoofs Adobe with a fake browser window to trick targets into installing a poisoned ScreenConnect client for persistent remote access.

Scammers have built a fake browser window that mimics an Adobe download page, and clicking through installs a booby-trapped remote access tool instead of a PDF reader.

Security firm Huntress reported a phishing campaign that spoofs Adobe's branding using a technique called browser-in-the-browser. Victims who click a link in an email land on a typosquatted domain, adoube.vu, that mimics an Adobe page. Instead of a real browser window, the page renders a fake one, complete with a fake address bar and padlock icon, showing a blurred PDF that supposedly requires "the latest version of Adobe" to open. Clicking "View Files" downloads not a PDF reader but a doctored version of ScreenConnect, a legitimate remote support tool, configured to phone home to the attackers.

Browser-in-the-browser fakes the one thing security training tells people to check, the address bar, which makes it harder to catch than typical phishing. Huntress said the attackers installed a second ScreenConnect client tied to their own infrastructure and ran a tool to hide the mouse cursor, suggesting hands-on-keyboard access rather than a scripted smash-and-grab. Huntress caught and shut down the intrusion before it went further, so it's unclear whether this was headed toward ransomware or something else.

Using a real, signed remote-support tool instead of custom malware is a familiar move. It's the same living-off-the-land trick abused for years with TeamViewer and AnyDesk, and it works precisely because a legitimate binary raises far fewer alarms than an obvious trojan.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →