216.73.217.22

Phishing Attack via Adobe-Themed Lure Delivering ScreenConnect and Credential Harvesting Tools

· Published 23/04/2026 08:27 · Modified 27/04/2026 14:31

Export JSON

Essential information

Published
23/04/2026 08:27
Modified
27/04/2026 14:31
Tags
2026-04-23 adobe lure credential harvesting password.exe phishing phone link remote access screenconnect social engineering uri handler exploitation
Related entities
3 observables, 19 techniques (mitre), 2 malware, 1 others

Description

A campaign utilized a fraudulent Adobe-themed website to trick victims into downloading and executing software. Once initial access was established, threat actors conducted interactive operations deploying multiple malicious binaries including a tool named . The attackers also exploited the ms-phone URI handler to launch the application, attempting to socially engineer victims into linking their mobile devices to potentially capture notifications, authentication prompts, and sensitive information. The attack demonstrates a multi-stage compromise focusing on persistence establishment, credential theft, and preparation for potential lateral movement across the victim's network infrastructure.

External references