Huntress investigated two late-August phishing intrusions in which attackers used browser-in-the-browser (BiTB) pages impersonating Adobe Acrobat or Reader to convince victims to install unauthorized ScreenConnect remote-management clients. Victims were led through malicious links and fake CAPTCHA or PDF-viewer lures to counterfeit Adobe browser windows that displayed the legitimate-looking get.adobe.com address within page content.
In each incident, the initial ScreenConnect installation downloaded and installed a second rogue ScreenConnect client, providing redundant service-based persistence and remote-access channels. The attackers also ran HideCursor.exe or HideUL.exe to conceal interactive activity; Huntress contained both intrusions before additional compromise. Microsoft Defender detected a command associated with patch.msi in one case but did not stop deployment of the second ScreenConnect client.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
On August 31, a victim interacted with a phishing message delivered through AT&T Office@Hand that led to the same fake Adobe Reader browser-in-the-browser template. An Adobe-update-themed installer deployed a ScreenConnect client, which retrieved a second client; both were registered as Windows services, and the actor ran HideUL.exe after deployment.
On August 25, Huntress detected malicious activity after a Gmail user followed a phishing link through fake CAPTCHA and Adobe PDF Reader browser-in-the-browser pages. The victim installed a rogue ScreenConnect client that downloaded a second client, established redundant service-based persistence, and was used to run HideCursor.exe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.