Phishing Campaign Uses Fake Adobe Pages to Distribute ScreenConnect Malware
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A phishing campaign is targeting financial organizations by using counterfeit Adobe Document Cloud pages to install ScreenConnect malware on victim machines. The attackers exploit trust in Adobe's services, utilizing a sophisticated phishing kit named 'RatPressto' that leverages compromised WordPress sites to evade detection. Phishing emails are crafted to appear as legitimate corporate communications, making them difficult to identify. The operation is well-structured and poses a significant threat to enterprise security. Currently, there are no specific numbers of victims reported, but the campaign is ongoing and evolving. Security professionals are advised to remain vigilant against such deceptive tactics.
Key Points: • Hackers are using fake Adobe Document Cloud pages to deliver ScreenConnect malware. • The phishing campaign targets financial organizations and employs a sophisticated kit named 'RatPressto'. • Phishing emails mimic legitimate corporate communications, complicating detection efforts.