ThreatCluster

Phishing Campaign Uses Fake Adobe Pages to Distribute ScreenConnect Malware

First seen 29 May 2026, 20:09 UTC GbhackersCybersecuritynews 92% similarity 62

Article Content

Browse articles
ThreatCluster

A phishing campaign is targeting financial organizations by using counterfeit Adobe Document Cloud pages to install ScreenConnect malware on victim machines. The attackers exploit trust in Adobe's services, utilizing a sophisticated phishing kit named 'RatPressto' that leverages compromised WordPress sites to evade detection. Phishing emails are crafted to appear as legitimate corporate communications, making them difficult to identify. The operation is well-structured and poses a significant threat to enterprise security. Currently, there are no specific numbers of victims reported, but the campaign is ongoing and evolving. Security professionals are advised to remain vigilant against such deceptive tactics.

Key Points: • Hackers are using fake Adobe Document Cloud pages to deliver ScreenConnect malware. • The phishing campaign targets financial organizations and employs a sophisticated kit named 'RatPressto'. • Phishing emails mimic legitimate corporate communications, complicating detection efforts.

ThreatCluster AI

Timeline

2026-05-29
Phishing campaign identified
A sophisticated phishing campaign using fake Adobe Document Cloud pages to install malware was reported, targeting financial organizations.
Cybersecuritynews
2026-05-29
Use of 'RatPressto' phishing kit confirmed
The campaign utilizes a phishing kit named 'RatPressto', which exploits compromised WordPress sites.
Gbhackers

Community

Browse all →