logo

Threat Actors Use Fake Adobe Reader Download To Deploy ScreenConnect

ID: d95c6246-887c-59d3-8aa6-e24b69edaceb

STIX ID: report--d95c6246-887c-59d3-8aa6-e24b69edaceb

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-16

Author: Varshini

...
...

Zscaler ThreatLabz identified a sophisticated campaign that lures victims to fake Adobe Acrobat download pages which deliver an obfuscated VBScript installer; the script uses PowerShell to bypass execution policies, pulls a secondary payload from cloud storage, compiles and runs a .NET loader entirely in memory, and deploys ConnectWise ScreenConnect as a persistent, stealthy backdoor. The report highlights in-memory execution, string/method fragmentation and other anti-analysis techniques, and recommends behavioral monitoring and detection of anomalous PowerShell executions and process masquerading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.