Phishing Attack via Adobe-Themed Lure Delivering ScreenConnect and Credential Harvesting Tools

April 27, 2026, 2:31 p.m.

Description

A phishing campaign utilized a fraudulent Adobe-themed website to trick victims into downloading and executing ScreenConnect remote access software. Once initial access was established, threat actors conducted interactive operations deploying multiple malicious binaries including a credential harvesting tool named password.exe. The attackers also exploited the ms-phone URI handler to launch the Phone Link application, attempting to socially engineer victims into linking their mobile devices to potentially capture notifications, authentication prompts, and sensitive information. The attack demonstrates a multi-stage compromise focusing on persistence establishment, credential theft, and preparation for potential lateral movement across the victim's network infrastructure.

Date

  • Created: April 23, 2026, 8:27 a.m.
  • Published: April 23, 2026, 8:27 a.m.
  • Modified: April 27, 2026, 2:31 p.m.

Indicators

  • 499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a
  • 18399555137b889a51eb543ddf01b3b7471a6e20453ee24801f8895528e7632f
  • https://still-smoke-8dac.matthewrobertoo6467.workers.dev/en/

Attack Patterns

Additional Informations

  • multifixcargas.com.br