<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve" -->

---
title: Huntress Uncovers Phishing Attacks Using Fake Browser...
description: Huntress researchers uncovered two phishing campaigns in August that used browser-in-the-browser (BiTB) fake windows mimicking Adobe&#x27;s site to trick victims...
canonical: https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools | daily.dev
og:description: Huntress researchers uncovered two phishing campaigns in August that used browser-in-the-browser (BiTB) fake windows mimicking Adobe&#x27;s site to trick victims...
og:url: https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve
og:image: https://api.daily.dev/og/posts/prStsFxvE.png
og:image:alt: Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

**[IT Security Guru](https://daily.dev/sources/itsecurityguru)** · 3 min read · 0 upvotes · 0 comments

## Summary

Huntress researchers uncovered two phishing campaigns in August that used browser-in-the-browser (BiTB) fake windows mimicking Adobe's site to trick victims into downloading a fake Adobe Reader update, which actually installed legitimate ScreenConnect RMM software. Attackers deployed redundant ScreenConnect clients and defence-evasion tools (HideCursor.exe, HideUL.exe) to maintain stealthy persistent access. Huntress intervened in both cases before further damage. The company's 2026 Cyber Threat Report found RMM abuse rose 277% year-on-year and featured in nearly a quarter of investigated incidents, and it recommends restricting RMM installation, maintaining approved software inventories, and monitoring for unauthorized ScreenConnect instances.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.itsecurityguru.org/2026/09/09/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools>

## Questions this post answers

### What is a browser-in-the-browser (BiTB) phishing attack?

A browser-in-the-browser attack fakes an entire browser window inside a webpage using HTML, CSS, and JavaScript, replicating an address bar, padlock icon, and a legitimate-looking URL. This makes it appear the victim is on a trusted site like get.adobe.com even though the whole window is fabricated, defeating the usual advice of checking the address bar.

_Security teams tracking phishing techniques like BiTB can follow emerging attack research on daily.dev._

### How are attackers abusing ScreenConnect in recent phishing campaigns?

Attackers disguise ScreenConnect installers as fake Adobe Reader updates delivered through phishing emails and browser-in-the-browser pages, then install two unauthorized ScreenConnect clients for redundant access. They pair this with defence-evasion tools like HideCursor.exe and HideUL.exe to hide activity, a technique Huntress observed in two separate incidents in August.

_Teams defending against RMM abuse can keep up with attacker tradecraft like this via daily.dev._

### How much has RMM software abuse grown in cyberattacks recently?

Remote monitoring and management (RMM) software abuse increased 277% year-on-year according to Huntress's 2026 Cyber Threat Report, and appeared in nearly a quarter of all incidents the company investigated. Organizations are advised to restrict who can install RMM tools, maintain an approved software inventory, and monitor for unauthorized ScreenConnect clients.

_Anyone building defenses against RMM abuse can track threat trends like this on daily.dev._

## Similar posts on daily.dev

- [RMM Abuse Explodes as Hackers Ditch Malware](https://daily.dev/posts/rmm-abuse-explodes-as-hackers-ditch-malware-v44l6tyt4) · Dark Reading · 0 upvotes · 0 comments
- [RMM Abuse: How Attackers Exploit Remote Access Tools](https://daily.dev/posts/rmm-abuse-how-attackers-exploit-remote-access-tools-kmwmtlqwz) · Huntress Blog · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools","url":"https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve"},"datePublished":"2026-09-09T14:47:30.622Z","dateModified":"2026-09-11T16:55:55.094Z","description":"Huntress researchers uncovered two phishing campaigns in August that used browser-in-the-browser (BiTB) fake windows mimicking Adobe's site to trick victims...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f7b3a98750ade7b880e7ffdc4feca46d?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f7b3a98750ade7b880e7ffdc4feca46d?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"IT Security Guru","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"IT Security Guru","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/ae9fe7d07c814192b35f86ad698fb374","url":"https://daily.dev/sources/itsecurityguru"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,phishing","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"IT Security Guru","item":"https://daily.dev/sources/itsecurityguru"},{"@type":"ListItem","position":3,"name":"Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/huntress-uncovers-phishing-attacks-using-fake-browser-pages-and-rogue-rmm-tools-prstsfxve#faq","mainEntity":[{"@type":"Question","name":"What is a browser-in-the-browser (BiTB) phishing attack?","acceptedAnswer":{"@type":"Answer","text":"A browser-in-the-browser attack fakes an entire browser window inside a webpage using HTML, CSS, and JavaScript, replicating an address bar, padlock icon, and a legitimate-looking URL. This makes it appear the victim is on a trusted site like get.adobe.com even though the whole window is fabricated, defeating the usual advice of checking the address bar. Security teams tracking phishing techniques like BiTB can follow emerging attack research on daily.dev."}},{"@type":"Question","name":"How are attackers abusing ScreenConnect in recent phishing campaigns?","acceptedAnswer":{"@type":"Answer","text":"Attackers disguise ScreenConnect installers as fake Adobe Reader updates delivered through phishing emails and browser-in-the-browser pages, then install two unauthorized ScreenConnect clients for redundant access. They pair this with defence-evasion tools like HideCursor.exe and HideUL.exe to hide activity, a technique Huntress observed in two separate incidents in August. Teams defending against RMM abuse can keep up with attacker tradecraft like this via daily.dev."}},{"@type":"Question","name":"How much has RMM software abuse grown in cyberattacks recently?","acceptedAnswer":{"@type":"Answer","text":"Remote monitoring and management (RMM) software abuse increased 277% year-on-year according to Huntress's 2026 Cyber Threat Report, and appeared in nearly a quarter of all incidents the company investigated. Organizations are advised to restrict who can install RMM tools, maintain an approved software inventory, and monitor for unauthorized ScreenConnect clients. Anyone building defenses against RMM abuse can track threat trends like this on daily.dev."}}]}
```

