Skip to main content
Reconnecting to live updates…

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

0
Medium
Published: 09/09/2026 (09/09/2026, 15:55:36 UTC)
Source: AlienVault OTX General

Description

Two sophisticated phishing campaigns employed browser-in-the-browser (BiTB) techniques to deceive victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing messages with malicious links redirecting targets to fake Adobe Reader update pages. The BiTB technique created convincing fake browser windows within webpages, displaying legitimate-looking Adobe URLs to bypass user awareness training. Victims were tricked into downloading ScreenConnect installers disguised as Adobe software updates. Each incident resulted in deployment of multiple rogue ScreenConnect instances for redundant persistence, followed by execution of defense-evasion binaries (HideCursor.exe and HideUL.exe) designed to hide attacker activities. The attacks established service-based persistence through Windows services, enabling continued remote access. Both campaigns were intercepted before further damage occurred, demonstrating how threat actors combine social engineering throughout the entire attack chain...

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 06:08:40 UTC

Technical Analysis

These phishing campaigns leveraged the browser-in-the-browser (BiTB) technique to create convincing fake browser windows within webpages, displaying legitimate Adobe URLs to deceive users. Victims were redirected to fake Adobe Reader update pages and tricked into downloading ScreenConnect installers masquerading as software updates. The attackers deployed multiple rogue ScreenConnect instances to maintain redundant persistence and executed defense-evasion binaries (HideCursor.exe and HideUL.exe) to hide their activities. Persistence was achieved through Windows service creation, allowing ongoing remote access. The campaigns were detected and stopped before additional harm occurred.

Potential Impact

If successful, the attacks would have allowed threat actors to gain persistent remote access to victim systems via rogue ScreenConnect installations, evade detection using specialized binaries, and maintain control through Windows service persistence. However, both campaigns were intercepted before further damage, preventing exploitation.

Defensive Guidance

No official patch or fix applies as this is a social engineering and malware deployment campaign. Mitigation focuses on user awareness training to recognize BiTB phishing techniques, blocking known malicious URLs and hashes associated with these campaigns, and monitoring for unauthorized ScreenConnect installations and suspicious Windows services. Since the campaigns were intercepted early, no urgent remediation is required beyond standard phishing defenses and endpoint monitoring.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/phishing-bitb-rmm-attacks"]
Adversary
null
Pulse Id
6aa181782eb83db70c28a2a7
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
hash752d5cdda2a1d93d27e38f98a5d23fc2
hash41d2097e8ac636a478aa011e12128c03b3b9bb3c8efca43d3c4f214ac8b1f07b
hash9f5910d69a4fbc56ff1854e7e0df3199fbfddd7fe6b374f7d816fa6ae70ef991
hashfc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2

Url

ValueDescriptionCopy
urlhttp://adoube.vu/2a8ed9baefcd
urlhttp://adoube.vu/filedocacess/file.html
urlhttp://selectstructure.com.au/freedom/adobedocument.html
urlhttp://wir.consultingics.com/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest&c=GOODVIBE&c=&c=&c=&c=&c=&c=&c=

Domain

ValueDescriptionCopy
domainadoube.vu
domainselectstructure.com.au
domainrelay.goldenmelon.us
domainrelay.illuminantgroup.net
domainscx.illuminantgroup.net
domainwir.consultingics.com

Threat ID: 6aa24590acd9273b49a1ef59

Added to database: 09/10/2026, 05:52:16 UTC

Last enriched: 09/10/2026, 06:08:40 UTC

Last updated: 09/10/2026, 16:40:50 UTC

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses