Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools
ID: 3ec80ef9-a55a-5c31-9762-4400f39c7d76
STIX ID: report--3ec80ef9-a55a-5c31-9762-4400f39c7d76
Feed Name: HackRead
Threat Score
ANY.RUN reports a phishing-to-remote-access campaign where a fake Word Online preview lures victims to download an MSI that is silently executed (Ninite), installs ScreenConnect remote access, and uses HideUL to conceal activity—creating an enterprise blind spot as trusted tools mask an active intrusion and delay prioritization and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
