Phishing campaign exploits Adobe branding and browser-in-the-browser trick to deploy rogue remote access software

Security researchers warn of a sophisticated phishing campaign using fake Adobe pages and a browser-in-the-browser technique to trick victims into installing malicious remote-access software, highlighting the growing abuse of trusted IT tools by threat actors.

Huntress has warned of a phishing campaign that uses Adobe branding and a browser-in-the-browser trick to push victims on to rogue remote-access software. According to the security researchers, the lure begins with an email link that sends users to a typosquatted domain, adoube.vu, which is made to resemble an Adobe download page. From there, the attack presents a fake browser frame, complete with a convincing-looking address bar and security icons, to make the page appear legitimate.

Inside that counterfeit window, victims are shown a blurred PDF and told the file is “secured” and requires the latest version of Adobe PDF Reader. A prominent “View Files” button then leads to what looks like a download process for a reader update, while malware is installed in the background. Huntress said the result is not a PDF reader at all, but a rogue ScreenConnect client.

ScreenConnect is a legitimate remote-support product, but in these incidents it was configured to give attackers persistent access to compromised machines. Huntress said the first malicious client connected to a ScreenConnect relay domain that looked legitimate, helping the activity avoid detection. The client then used Windows command shell and curl to fetch and install a second ScreenConnect instance tied to attacker-controlled infrastructure, with both versions set up for service-based persistence. The researchers also observed the use of HideCursor.exe to conceal mouse activity during the intrusion.

The firm said it has not identified the original phishing email itself, and it has not disclosed details about the intended target, so the full purpose of the campaign remains unclear. However, the pattern fits a broader trend in which threat actors abuse trusted remote-management tools rather than noisy commodity malware. Huntress urged employees to treat unexpected software update prompts with caution, verify downloads through trusted channels, and keep staff trained to spot suspicious file-viewing pages. It also recommended that IT teams restrict who can install remote-management tools, maintain an approved list of such software, and monitor for unapproved ScreenConnect clients, unusual relay connections and executables launched from user Downloads folders.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.