Itsecurityguru
Phishing Attacks Utilize Browser-in-the-Browser Technique with Rogue RMM Tools
Article Content
Huntress has identified two phishing attacks that employed a browser-in-the-browser (BiTB) technique to deceive victims into downloading malicious software disguised as an Adobe Reader update. Both incidents occurred in August 2026, starting with phishing emails that redirected victims to fake Adobe pages. The attackers used the BiTB method to create convincing fake browser windows, making it difficult for users to recognize the phishing attempt. Victims were prompted to download a ScreenConnect installer, a legitimate remote management tool, which allowed attackers to maintain persistent access to compromised devices. The first attack was detected on August 25, and the second on August 31, both involving the installation of rogue ScreenConnect instances and execution of defense-evasion binaries. Huntress intervened before the attacks could escalate further, highlighting the ongoing risk of social engineering techniques in cyber threats.
Key Points: • Phishing attacks utilized a browser-in-the-browser technique to deceive victims. • Attackers installed rogue instances of ScreenConnect for persistent access. • Huntress intervened before the attacks could escalate further.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.