Threat Advisory

Adobe BiTB Attack Deploys Rogue ScreenConnect Instances

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Browser-in-the-browser phishing attacks have been observed, utilizing a tactic where an attacker creates a fake browser window within a webpage to deceive targets. The attack sequence involves a phishing message with a malicious link redirecting victims to a landing page, where they are asked to view files via Adobe Acrobat. After clicking on the prompt, targets are presented with a bitB page within the webpage, which looks like an official Adobe webpage. This fake page instructs the victim to download and install ScreenConnect, ultimately leading to the deployment of multiple rogue ScreenConnect instances on their endpoints.

The attackers use social engineering techniques to convince victims to take the bait at every stage of the attack. The bitB technique is not new but highlights how persistently threat actors work to deceive targets. The attack chain involves a CAPTCHA lure, bitB, and persistence, with the target being convinced to click on an embedded link in the email, which takes them to a fake CAPTCHA lure. This phishing landing page displays a fake "safe access" browser check, asking visitors to confirm their browser to continue securely.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Browser-in-the-browser phishing attacks have been observed, utilizing a tactic where an attacker creates a fake browser window within a webpage to deceive targets. The attack sequence involves a phishing message with a malicious link redirecting victims to a landing page, where they are asked to view files via Adobe Acrobat. After clicking on the prompt, targets are presented with a bitB page within the webpage, which looks like an official Adobe webpage. This fake page instructs the victim to download and install ScreenConnect, ultimately leading to the deployment of multiple rogue ScreenConnect instances on their endpoints.

The attackers use social engineering techniques to convince victims to take the bait at every stage of the attack. The bitB technique is not new but highlights how persistently threat actors work to deceive targets. The attack chain involves a CAPTCHA lure, bitB, and persistence, with the target being convinced to click on an embedded link in the email, which takes them to a fake CAPTCHA lure. This phishing landing page displays a fake "safe access" browser check, asking visitors to confirm their browser to continue securely.[emaillocker id="1283"]

The significance of this attack lies in its ability to bypass social-engineering cues and deceive targets into downloading and installing rogue ScreenConnect instances. The attackers use legitimate domains and services to further avoid detection. The threat actors' motivation is unclear, but the campaign scale and victim counts are unknown. Defenders should be aware of this tactic and take necessary precautions to prevent similar attacks.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1204.002 User Execution Malicious File
Persistence T1543.003 Create or Modify System Process Windows Service
Defence Evasion T1070.004 Indicator Removal File Deletion
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu