RatPressto is a phishing operation and associated kit used in campaigns targeting financial organizations. The activity has been assessed with medium confidence as originating from a Brazilian threat actor. The operation impersonates Adobe Document Cloud notifications and uses compromised WordPress sites to host fake document-delivery pages designed to lure victims into downloading remote access software. The intrusion flow uses a staged social-engineering chain. Victims are directed from phishing emails to counterfeit Adobe-themed pages, after which a second-stage mechanism silently triggers delivery of a ScreenConnect installer through a hidden iframe. The actor abuses legitimate remote administration software rather than bespoke malware, enabling access while blending into normal enterprise tooling and traffic patterns. Reporting also indicates the use of additional staged payloads from code-hosting repositories and obfuscated batch scripts that remove traces after execution. Operationally, RatPressto shows infrastructure reuse and repeatable deployment tradecraft. Multiple compromised websites have hosted near-identical phishing pages, with only minor victim-tailored changes such as business-relevant filenames. The actor has relied on poorly secured WordPress environments for hosting and is assessed to have gained access through stolen credentials or exploitation of vulnerable plugins. The campaign demonstrates initial access via phishing, post-compromise remote access, persistence through installed remote administration tooling, and defense evasion through use of legitimate software and self-deleting scripts. No widely established aliases or sub-groups are currently available beyond the RatPressto name.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.