Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...
AI Analysis
Technical Summary
These phishing campaigns leveraged the browser-in-the-browser (BiTB) technique to create convincing fake browser windows within webpages, displaying legitimate Adobe URLs to deceive users. Victims were redirected to fake Adobe Reader update pages and tricked into downloading ScreenConnect installers masquerading as software updates. The attackers deployed multiple rogue ScreenConnect instances to maintain redundant persistence and executed defense-evasion binaries (HideCursor.exe and HideUL.exe) to hide their activities. Persistence was achieved through Windows service creation, allowing ongoing remote access. The campaigns were detected and stopped before additional harm occurred.
Potential Impact
If successful, the attacks would have allowed threat actors to gain persistent remote access to victim systems via rogue ScreenConnect installations, evade detection using specialized binaries, and maintain control through Windows service persistence. However, both campaigns were intercepted before further damage, preventing exploitation.
Mitigation Recommendations
No official patch or fix applies as this is a social engineering and malware deployment campaign. Mitigation focuses on user awareness training to recognize BiTB phishing techniques, blocking known malicious URLs and hashes associated with these campaigns, and monitoring for unauthorized ScreenConnect installations and suspicious Windows services. Since the campaigns were intercepted early, no urgent remediation is required beyond standard phishing defenses and endpoint monitoring.
Indicators of Compromise
- hash: f048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
- hash: 752d5cdda2a1d93d27e38f98a5d23fc2
- hash: 41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b
- hash: 9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991
- hash: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2
- url: http://adoube.vu/2a8ed9baefcd
- url: http://adoube.vu/filedocacess/file.html
- url: http://selectstructure.com.au/freedom/adobedocument.html
- url: http://wir.consultingics.com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GOODVIBE&c=&c=&c=&c=&c=&c=&c=
- domain: adoube.vu
- domain: selectstructure.com.au
- domain: relay.goldenmelon.us
- domain: relay.illuminantgroup.net
- domain: scx.illuminantgroup.net
- domain: wir.consultingics.com
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Description
Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
These phishing campaigns leveraged the browser-in-the-browser (BiTB) technique to create convincing fake browser windows within webpages, displaying legitimate Adobe URLs to deceive users. Victims were redirected to fake Adobe Reader update pages and tricked into downloading ScreenConnect installers masquerading as software updates. The attackers deployed multiple rogue ScreenConnect instances to maintain redundant persistence and executed defense-evasion binaries (HideCursor.exe and HideUL.exe) to hide their activities. Persistence was achieved through Windows service creation, allowing ongoing remote access. The campaigns were detected and stopped before additional harm occurred.
Potential Impact
If successful, the attacks would have allowed threat actors to gain persistent remote access to victim systems via rogue ScreenConnect installations, evade detection using specialized binaries, and maintain control through Windows service persistence. However, both campaigns were intercepted before further damage, preventing exploitation.
Defensive Guidance
No official patch or fix applies as this is a social engineering and malware deployment campaign. Mitigation focuses on user awareness training to recognize BiTB phishing techniques, blocking known malicious URLs and hashes associated with these campaigns, and monitoring for unauthorized ScreenConnect installations and suspicious Windows services. Since the campaigns were intercepted early, no urgent remediation is required beyond standard phishing defenses and endpoint monitoring.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/phishing-bitb-rmm-attacks"]
- Adversary
- null
- Pulse Id
- 6aa181782eb83db70c28a2a7
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashf048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35 | — | |
hash752d5cdda2a1d93d27e38f98a5d23fc2 | — | |
hash41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b | — | |
hash9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991 | — | |
hashfc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://adoube.vu/2a8ed9baefcd | — | |
urlhttp://adoube.vu/filedocacess/file.html | — | |
urlhttp://selectstructure.com.au/freedom/adobedocument.html | — | |
urlhttp://wir.consultingics.com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GOODVIBE&c=&c=&c=&c=&c=&c=&c= | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainadoube.vu | — | |
domainselectstructure.com.au | — | |
domainrelay.goldenmelon.us | — | |
domainrelay.illuminantgroup.net | — | |
domainscx.illuminantgroup.net | — | |
domainwir.consultingics.com | — |
Threat ID: 6aa24590acd9273b49a1ef59
Added to database: 09/10/2026, 05:52:16 UTC
Last enriched: 09/10/2026, 06:08:40 UTC
Last updated: 09/10/2026, 16:40:50 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.