Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Published September 9, 2026

Attackers sent fake Adobe Reader update emails with fake browser windows inside them. When victims clicked, they installed a hidden remote-control tool called ScreenConnect that let attackers spy on their computers.

Report priority
Medium
Targets
phishing+3 more

How it works

  • Attackers sent phishing emails with fake Adobe Reader update links.
  • The links opened fake browser windows inside the email, making them look like real Adobe pages.
  • When victims clicked the fake update, they downloaded a rogue ScreenConnect remote-control tool disguised as an Adobe update.
  • The attackers installed multiple copies of ScreenConnect to keep control even if one was removed.
  • They also ran two hidden files, HideCursor.exe and HideUL.exe, to hide their activity from the victim.

What to do

Check your installed programs for any unknown ScreenConnect entries. Look for suspicious files like HideCursor.exe or HideUL.exe in your Program Files or AppData folders. If you see these, uninstall any unknown ScreenConnect programs immediately using your system's uninstaller.

Scan your computer with a trusted antivirus program to remove any hidden files. Check your email for any suspicious Adobe update messages and report them to your IT team. If you suspect your computer is compromised, contact your IT department for further assistance.

Technical details

Affected software: phishing, screenconnect, rmm, browser-in-the-browser

An employee at a mid-sized company received an email saying their Adobe Reader needed an update. The email had a link that opened a fake browser window inside the email, showing a page that looked like Adobe's real update site. When the employee clicked the fake update button, it installed a hidden ScreenConnect remote-control tool on their computer. The attackers then used this tool to spy on the employee's work and hide their presence by running two hidden files.

A phishing campaign used browser-in-the-browser (BiTB) techniques to trick victims into installing rogue ScreenConnect remote management tools. Attackers sent phishing emails with malicious links leading to fake Adobe Reader update pages, which employed BiTB to simulate legitimate Adobe URLs and bypass security awareness training. Victims were lured into downloading fake Adobe installers that instead deployed multiple rogue ScreenConnect instances for redundant persistence.

The attackers then executed HideCursor.exe and HideUL.exe to conceal their activities, establishing service-based persistence via Windows services to maintain remote access. The campaign was tracked under OTX-6aa181782eb83db70c28a2a7, demonstrating how threat actors combine social engineering with technical evasion throughout the attack chain. Both incidents were intercepted before further damage occurred.