Fake Adobe Cloud Pages Deliver ScreenConnect Malware
Key Takeaways A sophisticated phishing campaign, dubbed “RatPressto,” is actively targeting financial organizations. Attackers use highly convincing fake Adobe Document Cloud pages to...
Key Takeaways
- A sophisticated phishing campaign, dubbed “RatPressto,” is actively targeting financial organizations.
- Attackers use highly convincing fake Adobe Document Cloud pages to deliver legitimate ScreenConnect remote access software as malware.
- The campaign leverages compromised WordPress sites to host the phishing kit, making detection difficult by blending malicious activity with normal enterprise traffic.
- Threat actors customize filenames to enhance legitimacy and utilize self-deleting batch scripts for stealth.
- Defenders should focus on monitoring for unauthorized ScreenConnect installations, outbound connections to specific ports, and securing WordPress environments.
A sophisticated phishing operation is currently targeting financial institutions, employing meticulously crafted fake Adobe Document Cloud pages to surreptitiously install ScreenConnect remote access malware on victim systems. This campaign’s intricate details were recently highlighted in a comprehensive report by Fortra’s Intelligence and Research Experts (FIRE) team.
Table Of Content
The attackers behind this operation have designed a highly structured and deceptive methodology, making it particularly challenging to detect. Their strategy involves integrating malicious activities seamlessly within typical enterprise software interactions, thereby evading conventional security measures.
The Phishing Modus Operandi
The campaign initiates with phishing emails designed to mimic authentic Adobe Document Cloud file-sharing notifications. These emails inform recipients that a confidential project document has been uploaded to Adobe Document Cloud and provide a link for viewing. Clicking this link directs victims to a compromised WordPress website that hosts a remarkably convincing replica of an Adobe page. This fake page is engineered to trick users into inadvertently downloading malware.
Fortra’s FIRE team identified and named the phishing kit facilitating this operation “RatPressto.” According to a report shared with Cyber Security News (CSN), the RatPressto kit is a privately maintained and reusable tool, meticulously developed to maximize victim trust while minimizing security detection. Intelligence suggests, with medium confidence, that a Brazilian threat actor is behind this campaign, a conclusion drawn from infrastructure analysis linked to São Paulo.
A defining characteristic of this campaign is its reliance on legitimate software to maintain a low profile. Instead of deploying custom-made malware, the attackers exploit ScreenConnect, a widely used remote administration tool, to establish full control over compromised machines. This tactic allows the malicious activity to blend in with legitimate business software traffic, significantly complicating its detection by standard security tools.
The campaign demonstrates consistent operational sophistication, utilizing reusable infrastructure across multiple deployments. Researchers observed numerous compromised websites hosting nearly identical phishing pages, with only minor alterations such as victim-specific filenames. This consistency strongly indicates a well-organized threat actor group managing a centralized, private phishing kit.
How the Fake Adobe Pages Work
The RatPressto kit employs a two-stage process designed to distract the victim while the malware installs itself silently in the background.
The first stage presents the victim with a highly believable fake Adobe page displaying a “Download Complete” message, complete with authentic Adobe branding and a loading animation. The primary purpose of this page is to occupy the victim’s attention while the malicious activity unfolds covertly.
Concurrently, in the background, a hidden iframe silently triggers the download of a ScreenConnect installer. By the time the victim sees instructions to open a file, the malicious payload has already been downloaded. Once executed, ScreenConnect installs discreetly, without any visible interface, and establishes a connection to a self-hosted command-and-control (C2) server located at cloud.zistopstoabetterlife.com on port 8041.
The attackers further stage additional payloads through GitHub repositories under the account “creativebobo.” They utilize heavily obfuscated batch scripts that self-delete after execution, effectively erasing traces of their activity. To enhance the illusion of legitimacy, filenames are customized to align with the victim’s business context, often incorporating the company name into the installer file.
Compromised WordPress Sites at the Core of the Attack
A critical component of this campaign involves the exploitation of poorly secured WordPress websites to host the phishing kit. Investigations revealed that multiple compromised sites had publicly exposed WordPress admin interfaces. This suggests that the attackers likely gained access by using stolen credentials or exploiting vulnerabilities in plugins, enabling them to directly upload the phishing files.
The consistent deployment of phishing kit files—including download.html, complete.php, and download.php—into WordPress-accessible directories across various unrelated websites strongly indicates that compromising WordPress admin panels is a deliberate and integral part of the attacker’s deployment strategy.
What You Should Do
- Secure WordPress Environments: Audit all WordPress installations for exposed admin interfaces (
/wp-admin/). Where possible, restrict public access to the wp-admin directory. - Implement Multi-Factor Authentication (MFA): Enforce MFA for all WordPress administrator accounts and other critical systems.
- Monitor for Unauthorized Remote Access Tools: Actively hunt for unauthorized installations of remote access tools like ScreenConnect.
- Network Monitoring: Configure alerts for outbound connections to TCP port 8041, which is used by the ScreenConnect C2 server in this campaign.
- Process Monitoring: Watch for
msiexecprocesses launching from temporary directories, as this is a key indicator of the infection chain. - Email Security Awareness: Educate users about sophisticated phishing techniques, especially those mimicking legitimate cloud services like Adobe Document Cloud.
- Block Malicious Infrastructure: Integrate the provided Indicators of Compromise (IoCs) into your security tools (firewalls, SIEM, EDR) to block known malicious domains and IP addresses.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| Domain | cloud.zistopstoabetterlife[.]com | Self-hosted ScreenConnect C2 server (port 8041) |
| Domain | ampliawifi[.]com | Actor-controlled WordPress deployment |
| Domain | gaheempreendimentos[.]com | Actor-controlled Cloudflare-protected deployment |
| Domain | c3po3090[.]com.br | Actor-controlled nameserver infrastructure |
| Domain | iconclinic[.]ae | Compromised victim WordPress site, wp-admin exposed |
| Domain | kinorot[.]co.il | Likely compromised victim infrastructure |
| Domain | vetcarebd[.]xyz | Compromised payload delivery host |
| Domain | nabellacouture[.]com | Compromised payload delivery host |
| Domain | birexo[.]icu | Additional phishing kit deployment |
| Domain | abpmed[.]com | Additional phishing kit deployment |
| IP Address | 177.154.191[.]148 | São Paulo, Brazil — actor hosting infrastructure |
| IP Address | 84.32.41[.]64 | Associated threat infrastructure |
| File | ScreenConnect.ClientSetup.msi | ScreenConnect installer payload |
| File | microsoftceo.exe | Malicious dropper executable |
| File | ceo.msi | MSI payload staged via GitHub |
| File | CapraAssetManagementInc.vbs | Victim-specific VBS dropper |
| URL Path | /wp-admin/ | Exposed WordPress admin interface used for kit deployment |
| URL Path | /download.html | Phishing kit stage 1 delivery file |
| URL Path | /complete.php | Phishing kit stage 2 PHP file |
| URL Path | /download.php | Hidden iframe payload trigger |
| GitHub Repo | creativebobo/ceoexe | GitHub staging repository for payloads |
| GitHub Repo | creativebobo/ceo | GitHub staging repository for payloads |
| Cloudflare Token | fcfd0b3135e24171980eef5488a4927b | Cloudflare telemetry beacon observed in newer kit samples |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.