logo

Fake Word Phishing Reveals Enterprise Blind Spot in Trusted Remote Access Tools

ID: 3ec80ef9-a55a-5c31-9762-4400f39c7d76

STIX ID: report--3ec80ef9-a55a-5c31-9762-4400f39c7d76

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Owais Sultan

...
...

ANY.RUN reports a phishing-to-remote-access campaign where a fake Word Online preview lures victims to download an MSI that is silently executed (Ninite), installs ScreenConnect remote access, and uses HideUL to conceal activity—creating an enterprise blind spot as trusted tools mask an active intrusion and delay prioritization and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.