Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
Brief
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.
Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.
Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.
Fake browser makes phishing harder to spot
BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript.
