Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Scheme Targets Finance Firms via Adobe Page Fakes

Phishing Scheme Targets Finance Firms via Adobe Page Fakes

Posted on May 29, 2026 By CWS

A recent phishing campaign is deceiving financial companies by using counterfeit Adobe Document Cloud pages to install ScreenConnect malware on targeted systems. This operation is intricately designed, merging seamlessly with usual enterprise software activities.

Deceptive Tactics in Phishing Emails

The attackers initiate their strategy by dispatching phishing emails masquerading as legitimate Adobe Document Cloud file-sharing alerts. Recipients are informed of a confidential project document available for viewing, with a link directing them to a bogus Adobe page.

This link, however, guides users to a compromised WordPress site hosting an authentic-looking Adobe page, tricking them into unknowingly downloading malware. The malicious campaign, identified by Fortra’s Intelligence and Research Experts (FIRE) team, is dubbed ‘RatPressto’.

The phishing kit employed is not only reusable and privately managed but also enhances victim trust while evading security detection. Based on infrastructure linked to São Paulo, the campaign is believed to originate from a Brazilian threat actor.

Exploiting Legitimate Software

What sets this campaign apart is its use of legitimate software for concealment. Instead of creating custom malware, the attackers exploit ScreenConnect, a common remote administration tool, to gain control over infected systems.

The integration of malicious activities with regular business software traffic complicates detection by standard security tools. This campaign exhibits operational maturity, deploying a consistent infrastructure across multiple operations.

Numerous compromised websites were discovered hosting nearly identical phishing pages, differing only in victim-specific file names, suggesting a centralized management of a private phishing kit by a single group.

Role of Compromised WordPress Sites

A critical element of this operation is the misuse of inadequately secured WordPress sites to host the phishing kit. Investigators found multiple sites with exposed WordPress admin interfaces, likely accessed through stolen credentials or exploited plugins.

The phishing kit includes files like download.html, complete.php, and download.php, placed in WordPress-accessible directories. The pattern’s consistency indicates a deliberate tactic of compromising WordPress admin panels during deployment.

Organizations are urged to secure their WordPress environments by reviewing admin interfaces for exposure, implementing multi-factor authentication, and monitoring for unauthorized ScreenConnect installations. Network security should also focus on detecting outbound connections to TCP port 8041 and msiexec processes from temporary directories.

The indicators of compromise (IoCs) include domains such as cloud.zistopstoabetterlife.com, various compromised WordPress sites, and GitHub repositories used for staging malicious payloads.

For more updates, follow our coverage on Google News, LinkedIn, and X, and set CSN as a preferred source for the latest cybersecurity news.

Cyber Security News Tags:Adobe Document Cloud, Brazilian threat actor, cyber attack, Cybersecurity, financial sector, Fortra, Malware, network security, Phishing, RatPressto, remote access, ScreenConnect, threat intelligence, WordPress

Post navigation

Previous Post: AI-Driven Cyberattacks by Russian Group Target Ukraine
Next Post: Zero-Day Vulnerability in Gogs Allows Remote Code Execution

Related Posts

Critical Backdoor in WordPress Plugin Exposes Admin Access Critical Backdoor in WordPress Plugin Exposes Admin Access Cyber Security News
Gemini CLI Flaw Allows Arbitrary Code Execution in CI/CD Gemini CLI Flaw Allows Arbitrary Code Execution in CI/CD Cyber Security News
Insider Threats in 2025 Detection and Prevention Strategies Insider Threats in 2025 Detection and Prevention Strategies Cyber Security News
FEMITBOT Network Abuses Telegram for Crypto Scams FEMITBOT Network Abuses Telegram for Crypto Scams Cyber Security News
Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns Pro-Iranian Hacktivists Targeting US Networks Department of Homeland Security Warns Cyber Security News
BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware BlueNoroff Hackers Weaponize Zoom App to Attack System Using Infostealer Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected
  • Hackers Use Evolving Phishing Code to Evade Detection
  • Critical ownCloud Vulnerability Used in Targeted Attacks
  • AI Systems Under Siege: RCE and API Key Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Berlin Stands Firm Against Hackers in Data Breach Case
  • Cosmos EVM Vulnerability Exposed, Multiple Blockchains Affected
  • Hackers Use Evolving Phishing Code to Evade Detection
  • Critical ownCloud Vulnerability Used in Targeted Attacks
  • AI Systems Under Siege: RCE and API Key Threats

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark