As cited
Copy frozen at (site build).
threat intel
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
Huntress observed phishing attacks delivering browser-in-the-browser pages to deceive users into accessing credential harvesting sites. Attackers established persistence through rogue ScreenConnect installations, a remote monitoring and management tool, to maintain access and evade detection.
Why it matters: Organizations face credential compromise and unauthorized remote access from these phishing campaigns; security teams should monitor for suspicious ScreenConnect deployments and educate users on browser-in-the-browser deception tactics.
- Source published
- First seen by Cybersecurity Tracker