Skip to content
ThreatCluster

Phishing Campaign Uses Fake Adobe Pages to Distribute ScreenConnect Malware

First seen 29 May 2026, 20:09 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 30, 2026 at 19:54 UTC

A phishing campaign is targeting financial organizations by using counterfeit Adobe Document Cloud pages to install ScreenConnect malware on victim machines. The attackers exploit trust in Adobe's services, utilizing a sophisticated phishing kit named 'RatPressto' that leverages compromised WordPress sites to evade detection. Phishing emails are crafted to appear as legitimate corporate communications, making them difficult to identify. The operation is well-structured and poses a significant threat to enterprise security. Currently, there are no specific numbers of victims reported, but the campaign is ongoing and evolving. Security professionals are advised to remain vigilant against such deceptive tactics.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 103d ago How this analysis works

Timeline

2026-05-29
Phishing campaign identified
A sophisticated phishing campaign using fake Adobe Document Cloud pages to install malware was reported, targeting financial organizations.
Cybersecuritynews
2026-05-29
Use of 'RatPressto' phishing kit confirmed
The campaign utilizes a phishing kit named 'RatPressto', which exploits compromised WordPress sites.
Gbhackers

More articles in this cluster (2)