Fake Adobe Reader Pages Install Remote Access Malware

An email says a document is waiting. The link opens a page with blurred files and a familiar Adobe prompt explaining that Reader must be updated before the documents can be viewed.

Clicking the button appears to open a new browser window on an official Adobe address. The padlock, favicon, and address bar all look correct.

Fake Adobe Reader pages build that window inside the malicious site. The “Adobe update” installs remote-access software controlled by the attacker.

Fake Adobe Reader document page with blurred shared files

Overview

The phishing pages imitate Adobe document viewing and updates

Huntress investigated two related attacks in August 2026 that began with phishing messages and led to pages claiming Adobe PDF Reader was required to open shared files. One path used the typosquatted domain adoube.vu, while another used a compromised or attacker-controlled page under a different domain.

The sites displayed blurred document previews and instructions to select “View Files.” Some visitors first saw a fake “Safe access” browser check resembling a CAPTCHA. Each stage was designed to make the final software download feel like a normal document-viewing requirement.

A browser-in-the-browser window hides the real domain

After the visitor interacts with the page, it creates a fake browser window inside the existing webpage. This technique is known as browser-in-the-browser, or BitB. The attacker can draw an address bar, padlock, tabs, favicon, and a convincing get.adobe.com address.

The displayed Adobe URL is not the browser’s real address bar. It is ordinary page content made to look like browser chrome, so it can show any trusted domain the attacker chooses.

The downloaded installer deploys rogue ScreenConnect access

The supposed Reader installer is actually a ScreenConnect client or an MSI package that installs remote-management software. ScreenConnect is a legitimate support product, but in this campaign it was configured to give unauthorized operators persistent access to the victim’s computer.

Huntress found multiple rogue ScreenConnect instances and defense-evasion tools named HideCursor.exe and HideUL.exe. The security company interrupted both observed incidents before the attackers progressed further.

  • The attacks started with phishing messages containing malicious links.
  • One chain used adoube.vu, a misspelling of Adobe.
  • A fake browser check and blurred document preview prepared the victim.
  • The page rendered a false browser window showing a legitimate-looking Adobe URL.
  • The “Reader” download was actually ScreenConnect remote-access software.
  • A second incident disguised the installer as AdbRdBkUpsStUp.msi.
  • Multiple remote-access clients were installed for persistence.
  • Additional tools attempted to hide attacker activity on the screen.
  • Adobe and ScreenConnect were abused brands and tools, not the operators of the phishing campaign.

The campaign is especially dangerous in offices where PDF documents arrive constantly. An invoice, signed agreement, voicemail attachment, or shared report provides a believable reason for the recipient to expect Adobe software.

Attackers do not need to copy every Adobe feature. They only need enough familiar elements to keep the victim moving from the message to the preview, from the preview to the update, and from the update to the installer.

The request can also arrive during a real business process. Someone waiting for a contract or invoice may assume the page relates to that expected document, even when the sender and file-sharing route have not been verified.

Pausing to contact the supposed sender through a known telephone number can break the chain before any software reaches the computer.

Why Checking the Address Bar Can Fail on This Page

People are correctly taught to inspect the address bar before entering information or downloading software. Browser-in-the-browser attacks exploit that habit by showing a second, fake address bar that exists entirely inside the webpage.

The attacker controls every pixel in that imitation window. It can display get.adobe.com, a padlock, an Adobe icon, and familiar browser buttons even though the real tab remains on a malicious domain.

A user may focus on the inner window because it looks like the active browser. On a smaller laptop screen, or when the page dims the background, the real address bar can be easy to overlook.

Browser-in-the-browser window showing a fake official Adobe address

The false window cannot behave exactly like genuine browser chrome. It usually cannot be dragged beyond the boundaries of the original webpage, and clicking its address text may not place a real cursor in the browser’s location field.

Those tests can help, but the safest response is simpler. A document-sharing page should not require installing Reader from a prompt embedded inside the document page. Close it and obtain Adobe software only by manually visiting Adobe or using the application’s built-in updater.

The campaign also uses several layers before the download, which reduces the chance that the user will stop at the final step. After completing a “safe access” check and seeing file previews, the update prompt feels like the last ordinary obstacle.

This staged design is important. The phishing email creates curiosity, the browser check creates legitimacy, the blurred files create anticipation, and the fake Adobe window supplies authority. No single screen has to carry the entire deception.

Company, Address, and Fulfillment Checks

The adoube.vu address is a deliberate lookalike

One attack used adoube.vu, which rearranges letters in the Adobe name. A visitor scanning quickly may read what they expect rather than the actual spelling.

The page later shows get.adobe.com inside the fake browser window. That second address does not replace the real typosquatted destination and does not establish any connection to Adobe.

The inner address bar is webpage content

Browser-in-the-browser does not compromise the real address bar. It imitates it. The genuine browser still knows the actual page address, but the site draws another interface below it and encourages the user to trust the copy.

Security decisions must be based on the outer browser interface and on independently reached vendor pages, not on a window rendered by the site being evaluated.

The installer belongs to a remote-support chain

The first observed payload used a ScreenConnect ClientSetup executable. The second disguised an MSI installer as an Adobe Reader update. Both led to unauthorized ScreenConnect clients that contacted attacker-selected relay infrastructure.

Remote-management tools can allow screen viewing, command execution, file transfer, and persistent reconnection. A legitimate tool becomes dangerous when installed without informed approval and enrolled into an attacker’s account.

Huntress confirmed two related incidents

Huntress documented the phishing messages, Adobe-themed BitB pages, rogue ScreenConnect installers, persistence, and defense-evasion files. Its incident-response team stopped both attacks before later objectives could be observed.

The evidence confirms the delivery and remote-access stages. It does not establish every action the operators might have taken if uninterrupted, so claims about later theft or ransomware should remain possibilities rather than reported outcomes in these two cases.

That evidence boundary is useful for victims. The installation of unauthorized remote software is enough to require serious containment even without proof that a bank account or file was opened. Waiting for visible theft gives the operator more time.

How the Fake Adobe Reader Update Scam Works

Step 1: A phishing message presents a shared document

The victim receives an email or cloud-communications message with a link to view files. Huntress did not recover every original lure, but its telemetry tied both incidents to users following malicious links from messages.

One incident involved a message accessed through Gmail. Another used AT&T Office@Hand, based on RingCentral, as the delivery channel.

Step 2: The landing page displays a safety check or file preview

The first path shows a fake “Safe access” browser check. After interaction, it redirects to a page with blurred documents and an Adobe PDF Reader message.

The second path reaches a similar Adobe-themed template. Reusing the design across different domains lets the attackers change delivery infrastructure while keeping the same persuasion flow.

Step 3: The site opens a fake browser window

When the victim chooses to view the files, the page renders a BitB window. Its address bar displays an official-looking Adobe URL, even though the outer page is still controlled by the attacker.

The false window instructs the victim to download Reader, open the Downloads folder, and run the installer.

Fraudulent Adobe Reader installer delivering ScreenConnect remote access

Step 4: The fake update installs ScreenConnect

The downloaded file is not Adobe Reader. Depending on the incident, it is a ScreenConnect executable or an MSI with an Adobe-like name.

Running it enrolls the machine into remote-access infrastructure controlled by the attackers. The user has effectively installed the operator’s doorway while believing they installed a document reader.

The installed service may use a normal product name and digital signature because the underlying remote-support software is real. Detection therefore depends on whether the tool was authorized, who controls its instance, and which relay it contacts.

Step 5: Additional clients create persistent access

Huntress found more than one rogue ScreenConnect instance in each chain. Multiple clients can give the attacker another way back if one service is noticed or removed.

The tools contacted separate relay and payload-hosting domains, allowing the operator to manage the compromised endpoint remotely.

Step 6: Defense-evasion tools hide visible activity

The attackers deployed files named HideCursor.exe and HideUL.exe. These tools were intended to conceal on-screen activity and reduce the chance that the person at the computer would notice remote actions.

Huntress stopped the observed attacks at this stage. On an unmanaged computer, persistent remote access could be used for account theft, financial fraud, data theft, or delivery of additional malware.

Warning Signs on a Fake Document Viewer

  • An unexpected document message requires a software download.
  • The real browser address contains a misspelling such as adoube instead of Adobe.
  • A “Safe access” or CAPTCHA-style page appears before the document.
  • The site displays blurred files but will not identify the sender clearly.
  • A second browser window appears inside the webpage.
  • The inner address bar shows Adobe while the outer address bar shows another domain.
  • The update downloads directly from unfamiliar storage or relay infrastructure.
  • The file is an EXE or MSI with an unusual Reader-style name.
  • The document page tells you to install software before verifying the file.
  • ScreenConnect appears even though you did not request remote support.

Adobe Reader should be installed from Adobe’s website reached manually, a trusted software-management system, or its built-in updater. A shared-document page should never choose the installer for you.

What to Do if You Have Fallen Victim to This Scam

  1. Disconnect the computer from the network. Turn off Wi-Fi or unplug Ethernet to interrupt active remote sessions. Do not continue using the machine for email, banking, or passwords.
  2. Tell your workplace security team immediately. Provide the message, URL, downloaded file name, approximate installation time, and any ScreenConnect window or service you noticed.
  3. Do not rely on closing the visible program. The campaign installed multiple remote-access clients. Administrators should inventory ScreenConnect services, startup items, scheduled tasks, relay connections, and additional payloads.
  4. Change credentials from a clean device. Begin with primary email and work identity accounts, then financial services, cloud storage, and any password entered or stored on the affected computer.
  5. Revoke sessions and review authentication changes. Remove unfamiliar devices, tokens, forwarding rules, connected apps, and MFA methods. Password changes alone may not end every active session.
  6. Run a full incident-response scan. Malwarebytes can help find remote-access components and related malware. AdGuard can reduce exposure to malicious pages and advertising, but a computer with confirmed rogue RMM access may need professional reimaging.
  7. Check for financial and data access. Review bank activity, cryptocurrency wallets, browser-saved passwords, cloud downloads, and sent email. Notify affected institutions quickly.
  8. Preserve evidence before rebuilding. Security teams may need installer hashes, browser history, Windows logs, ScreenConnect configuration, and network records to determine the scope.
  9. Report the phishing infrastructure. Notify the email or communication provider, Adobe, the hosting providers, and the appropriate cybercrime authority. Ignore anyone offering paid remote cleanup after contacting you unexpectedly.

Frequently Asked Questions

What is browser-in-the-browser phishing?

It is a technique where a malicious webpage draws a fake browser window inside itself, including an address bar and padlock, to display a trusted-looking domain.

Was get.adobe.com actually compromised?

The documented page only displayed that address inside a fake window. The attacker-controlled site did not become legitimate by drawing Adobe’s URL.

Is ScreenConnect malware?

ScreenConnect is legitimate remote-support software. In this campaign, attackers installed unauthorized clients configured for their own access, making the deployment malicious.

Can opening the phishing page alone install the remote tool?

The observed chain required the victim to download and run the supposed Reader installer. Viewing the page is not the same as executing the file, but the page should still be closed and reported.

What if Adobe Reader is already installed?

That is another reason the prompt is suspicious. Verify Reader updates through the installed application or Adobe’s site, never through a document link.

Is removing one ScreenConnect client enough?

Not necessarily. Huntress observed multiple rogue instances and additional defense-evasion files. A complete endpoint investigation or trusted reimage is safer.

The Bottom Line

The fake Adobe Reader pages combine a familiar document lure with a browser window that lies about its own address. The convincing get.adobe.com display is page artwork, not proof of location.

The downloaded “update” installs remote-access software, giving attackers a persistent route into the computer. Adobe Reader is the disguise, not the payload.

If you ran the installer, disconnect the machine and treat it as remotely compromised. Remove every unauthorized access path, recover accounts from a clean device, and reimage the system when the scope cannot be proven safe.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

South Australia Police Phone Scam: How Spoofed Calls Steal Money Today

Next

Elderly Sweepstakes Restitution Scam: Fake Recovery Offers Fully Exposed