home.social

#adobereader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #adobereader, aggregated by home.social.

  1. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

    Pulse ID: 6aa181782eb83db70c28a2a7
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #AdobeReader #Browser #CyberSecurity #FakeBrowser #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ScreenConnect #SocialEngineering #Windows #bot #AlienVault

  2. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

    Pulse ID: 6aa181782eb83db70c28a2a7
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #AdobeReader #Browser #CyberSecurity #FakeBrowser #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ScreenConnect #SocialEngineering #Windows #bot #AlienVault

  3. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

    Pulse ID: 6aa181782eb83db70c28a2a7
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #AdobeReader #Browser #CyberSecurity #FakeBrowser #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ScreenConnect #SocialEngineering #Windows #bot #AlienVault

  4. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

    Pulse ID: 6aa181782eb83db70c28a2a7
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #AdobeReader #Browser #CyberSecurity #FakeBrowser #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ScreenConnect #SocialEngineering #Windows #bot #AlienVault

  5. Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

    Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

    Pulse ID: 6aa181782eb83db70c28a2a7
    Pulse Link: otx.alienvault.com/pulse/6aa18
    Pulse Author: AlienVault
    Created: 2026-09-09 15:55:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Adobe #AdobeReader #Browser #CyberSecurity #FakeBrowser #InfoSec #OTX #OpenThreatExchange #Phishing #RAT #RCE #ScreenConnect #SocialEngineering #Windows #bot #AlienVault