Scammers have built a fake browser window that mimics an Adobe download page, and clicking through installs a booby-trapped remote access tool instead of a PDF reader.
Security firm Huntress reported a phishing campaign that spoofs Adobe's branding using a technique called browser-in-the-browser. Victims who click a link in an email land on a typosquatted domain, adoube.vu, that mimics an Adobe page. Instead of a real browser window, the page renders a fake one, complete with a fake address bar and padlock icon, showing a blurred PDF that supposedly requires "the latest version of Adobe" to open. Clicking "View Files" downloads not a PDF reader but a doctored version of ScreenConnect, a legitimate remote support tool, configured to phone home to the attackers.
Browser-in-the-browser fakes the one thing security training tells people to check, the address bar, which makes it harder to catch than typical phishing. Huntress said the attackers installed a second ScreenConnect client tied to their own infrastructure and ran a tool to hide the mouse cursor, suggesting hands-on-keyboard access rather than a scripted smash-and-grab. Huntress caught and shut down the intrusion before it went further, so it's unclear whether this was headed toward ransomware or something else.
Using a real, signed remote-support tool instead of custom malware is a familiar move. It's the same living-off-the-land trick abused for years with TeamViewer and AnyDesk, and it works precisely because a legitimate binary raises far fewer alarms than an obvious trojan.