Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Poison Claude Sells AI Tokens From Fake Accounts and Free Credits
August 5, 2026
Greatness PhaaS Bypasses Email Security, MFA to Hijack Microsoft 365 Accounts
August 5, 2026
Microsoft Awards Record $20M to 562 Researchers in Biggest Bug Bounty Year
August 5, 2026
Home/Threats/Fake Adobe Cloud Pages Deliver ScreenConnect Malware
Threats

Fake Adobe Cloud Pages Deliver ScreenConnect Malware

Key Takeaways A sophisticated phishing campaign, dubbed “RatPressto,” is actively targeting financial organizations. Attackers use highly convincing fake Adobe Document Cloud pages to...

Jennifer sherman
Jennifer sherman
May 29, 2026 5 Min Read
57 0

Key Takeaways

  • A sophisticated phishing campaign, dubbed “RatPressto,” is actively targeting financial organizations.
  • Attackers use highly convincing fake Adobe Document Cloud pages to deliver legitimate ScreenConnect remote access software as malware.
  • The campaign leverages compromised WordPress sites to host the phishing kit, making detection difficult by blending malicious activity with normal enterprise traffic.
  • Threat actors customize filenames to enhance legitimacy and utilize self-deleting batch scripts for stealth.
  • Defenders should focus on monitoring for unauthorized ScreenConnect installations, outbound connections to specific ports, and securing WordPress environments.

A sophisticated phishing operation is currently targeting financial institutions, employing meticulously crafted fake Adobe Document Cloud pages to surreptitiously install ScreenConnect remote access malware on victim systems. This campaign’s intricate details were recently highlighted in a comprehensive report by Fortra’s Intelligence and Research Experts (FIRE) team.

Table Of Content

  • Key Takeaways
  • The Phishing Modus Operandi
  • How the Fake Adobe Pages Work
  • Compromised WordPress Sites at the Core of the Attack
  • What You Should Do
  • Indicators of Compromise (IoCs)

The attackers behind this operation have designed a highly structured and deceptive methodology, making it particularly challenging to detect. Their strategy involves integrating malicious activities seamlessly within typical enterprise software interactions, thereby evading conventional security measures.

The Phishing Modus Operandi

The campaign initiates with phishing emails designed to mimic authentic Adobe Document Cloud file-sharing notifications. These emails inform recipients that a confidential project document has been uploaded to Adobe Document Cloud and provide a link for viewing. Clicking this link directs victims to a compromised WordPress website that hosts a remarkably convincing replica of an Adobe page. This fake page is engineered to trick users into inadvertently downloading malware.

Fortra’s FIRE team identified and named the phishing kit facilitating this operation “RatPressto.” According to a report shared with Cyber Security News (CSN), the RatPressto kit is a privately maintained and reusable tool, meticulously developed to maximize victim trust while minimizing security detection. Intelligence suggests, with medium confidence, that a Brazilian threat actor is behind this campaign, a conclusion drawn from infrastructure analysis linked to São Paulo.

A defining characteristic of this campaign is its reliance on legitimate software to maintain a low profile. Instead of deploying custom-made malware, the attackers exploit ScreenConnect, a widely used remote administration tool, to establish full control over compromised machines. This tactic allows the malicious activity to blend in with legitimate business software traffic, significantly complicating its detection by standard security tools.

The campaign demonstrates consistent operational sophistication, utilizing reusable infrastructure across multiple deployments. Researchers observed numerous compromised websites hosting nearly identical phishing pages, with only minor alterations such as victim-specific filenames. This consistency strongly indicates a well-organized threat actor group managing a centralized, private phishing kit.

How the Fake Adobe Pages Work

The RatPressto kit employs a two-stage process designed to distract the victim while the malware installs itself silently in the background.

The first stage presents the victim with a highly believable fake Adobe page displaying a “Download Complete” message, complete with authentic Adobe branding and a loading animation. The primary purpose of this page is to occupy the victim’s attention while the malicious activity unfolds covertly.

Concurrently, in the background, a hidden iframe silently triggers the download of a ScreenConnect installer. By the time the victim sees instructions to open a file, the malicious payload has already been downloaded. Once executed, ScreenConnect installs discreetly, without any visible interface, and establishes a connection to a self-hosted command-and-control (C2) server located at cloud.zistopstoabetterlife.com on port 8041.

The attackers further stage additional payloads through GitHub repositories under the account “creativebobo.” They utilize heavily obfuscated batch scripts that self-delete after execution, effectively erasing traces of their activity. To enhance the illusion of legitimacy, filenames are customized to align with the victim’s business context, often incorporating the company name into the installer file.

Compromised WordPress Sites at the Core of the Attack

A critical component of this campaign involves the exploitation of poorly secured WordPress websites to host the phishing kit. Investigations revealed that multiple compromised sites had publicly exposed WordPress admin interfaces. This suggests that the attackers likely gained access by using stolen credentials or exploiting vulnerabilities in plugins, enabling them to directly upload the phishing files.

The consistent deployment of phishing kit files—including download.html, complete.php, and download.php—into WordPress-accessible directories across various unrelated websites strongly indicates that compromising WordPress admin panels is a deliberate and integral part of the attacker’s deployment strategy.

What You Should Do

  • Secure WordPress Environments: Audit all WordPress installations for exposed admin interfaces (/wp-admin/). Where possible, restrict public access to the wp-admin directory.
  • Implement Multi-Factor Authentication (MFA): Enforce MFA for all WordPress administrator accounts and other critical systems.
  • Monitor for Unauthorized Remote Access Tools: Actively hunt for unauthorized installations of remote access tools like ScreenConnect.
  • Network Monitoring: Configure alerts for outbound connections to TCP port 8041, which is used by the ScreenConnect C2 server in this campaign.
  • Process Monitoring: Watch for msiexec processes launching from temporary directories, as this is a key indicator of the infection chain.
  • Email Security Awareness: Educate users about sophisticated phishing techniques, especially those mimicking legitimate cloud services like Adobe Document Cloud.
  • Block Malicious Infrastructure: Integrate the provided Indicators of Compromise (IoCs) into your security tools (firewalls, SIEM, EDR) to block known malicious domains and IP addresses.

Indicators of Compromise (IoCs):

Type Indicator Description
Domain cloud.zistopstoabetterlife[.]com Self-hosted ScreenConnect C2 server (port 8041)
Domain ampliawifi[.]com Actor-controlled WordPress deployment
Domain gaheempreendimentos[.]com Actor-controlled Cloudflare-protected deployment
Domain c3po3090[.]com.br Actor-controlled nameserver infrastructure
Domain iconclinic[.]ae Compromised victim WordPress site, wp-admin exposed
Domain kinorot[.]co.il Likely compromised victim infrastructure
Domain vetcarebd[.]xyz Compromised payload delivery host
Domain nabellacouture[.]com Compromised payload delivery host
Domain birexo[.]icu Additional phishing kit deployment
Domain abpmed[.]com Additional phishing kit deployment
IP Address 177.154.191[.]148 São Paulo, Brazil — actor hosting infrastructure
IP Address 84.32.41[.]64 Associated threat infrastructure
File ScreenConnect.ClientSetup.msi ScreenConnect installer payload
File microsoftceo.exe Malicious dropper executable
File ceo.msi MSI payload staged via GitHub
File CapraAssetManagementInc.vbs Victim-specific VBS dropper
URL Path /wp-admin/ Exposed WordPress admin interface used for kit deployment
URL Path /download.html Phishing kit stage 1 delivery file
URL Path /complete.php Phishing kit stage 2 PHP file
URL Path /download.php Hidden iframe payload trigger
GitHub Repo creativebobo/ceoexe GitHub staging repository for payloads
GitHub Repo creativebobo/ceo GitHub staging repository for payloads
Cloudflare Token fcfd0b3135e24171980eef5488a4927b Cloudflare telemetry beacon observed in newer kit samples

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Microsoft System64 Malware Exfiltrates Data via HuggingFace Datasets

Next Post

Fake OpenAI Codex UI Steals Authentication Tokens

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us