Phishing Attacks Utilize Browser-in-the-Browser Technique with Rogue RMM Tools

Phishing Attacks Utilize Browser-in-the-Browser Technique with Rogue RMM Tools

First seen 9 Sep 2026, 15:48 UTC HuntressItsecurityguru 61.5

Article Content

Browse articles
ThreatCluster

Huntress has identified two phishing attacks that employed a browser-in-the-browser (BiTB) technique to deceive victims into downloading malicious software disguised as an Adobe Reader update. Both incidents occurred in August 2026, starting with phishing emails that redirected victims to fake Adobe pages. The attackers used the BiTB method to create convincing fake browser windows, making it difficult for users to recognize the phishing attempt. Victims were prompted to download a ScreenConnect installer, a legitimate remote management tool, which allowed attackers to maintain persistent access to compromised devices. The first attack was detected on August 25, and the second on August 31, both involving the installation of rogue ScreenConnect instances and execution of defense-evasion binaries. Huntress intervened before the attacks could escalate further, highlighting the ongoing risk of social engineering techniques in cyber threats.

Key Points: • Phishing attacks utilized a browser-in-the-browser technique to deceive victims. • Attackers installed rogue instances of ScreenConnect for persistent access. • Huntress intervened before the attacks could escalate further.

Ask AI about this cluster

Timeline

2026-08-25
First phishing attack detected
A victim clicked a link in a phishing email and was redirected to a fake CAPTCHA page, leading to the installation of rogue ScreenConnect.
Itsecurityguru
2026-08-31
Second phishing attack detected
Another incident involved a malicious link delivered through AT&T Office@Hand, leading to the installation of unauthorized ScreenConnect instances.
Itsecurityguru
2026-09-09
Huntress reports on attacks
Huntress published findings on the phishing attacks, detailing the use of BiTB and rogue RMM tools.
Huntress