Fake Adobe Document Cloud Pages Spread ScreenConnect Malware
ID: 67115dbd-3318-53b1-a054-efc086d4f47c
STIX ID: report--67115dbd-3318-53b1-a054-efc086d4f47c
Feed Name: GBHackers
**Executive summary:** The RatPressto campaign uses convincing Adobe Document Cloud-themed phishing pages hosted on compromised WordPress sites to silently download and install ScreenConnect-based remote access tooling from attacker-controlled repositories (including GitHub), enabling persistent remote access and data theft from targeted financial organizations; the report includes reused page artifacts, victim-specific payload names, IPs/domains, and file artifacts and recommends securing WordPress admin panels, monitoring remote access tool usage, and user awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
