Threat reportPhishingTL-2026-0629
RatPressto Phishing Kit — Fake Adobe Document Cloud Pages Deliver ConnectWise ScreenConnect RAT
RatPressto Phishing Kit (TL-2026-0629), also tracked as RatPressto, is a medium-severity phishing campaign, first published 2026-05-29. It carries a reported Brazil nexus and is not formally attributed, affects ConnectWise ScreenConnect (remote support client), maps to 15 MITRE ATT&CK techniques (T1027, T1036, T1059), and is covered by 9 detection rules and 26 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 26Indicators of compromise
Key facts for TL-2026-0629
- Threat ID
- TL-2026-0629
- Also known as
- RatPressto
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- NONE
- Nation-state nexus
- Brazil
- Motivation
- FINANCIAL
- Target sectors
- financial
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 26
Malware and tooling in RatPressto Phishing Kit
Malware and tooling: ConnectWise ScreenConnect
How RatPressto Phishing Kit works
Fortra's FIRE team identified 'RatPressto', a reusable private phishing kit targeting financial organizations with fake Adobe Document Cloud 'Download Complete' pages hosted on compromised WordPress sites. A hidden iframe silently triggers a ConnectWise ScreenConnect installer, abusing the legitimate remote support tool as a RAT for full remote control. The operation is assessed with medium confidence to a Brazilian threat actor based on Sao Paulo-tied infrastructure.
RatPressto is a reusable, privately distributed phishing kit documented by Fortra's Intelligence and Research Experts (FIRE) team and publicly reported on 2026-05-29. The campaign primarily targets financial organizations and abuses the legitimate ConnectWise ScreenConnect remote support client as a remote access trojan (RAT), giving operators full interactive control of compromised endpoints while blending into environments where remote-support tooling is common.
The exploit chain begins with phishing emails that impersonate Adobe Document Cloud file-sharing notifications, claiming a confidential project document has been shared. Victims who click the 'View File'/download link are redirected to compromised WordPress sites (frequently with publicly exposed /wp-admin panels) that host a convincing fake Adobe 'Download Complete' page. The page renders Adobe branding and a loading animation purely as a distraction: while the victim reads on-screen instructions to open the file, a hidden iframe (download.php) has already silently fetched the payload. The delivery flow chains download.html (stage 1 lure), complete.php (stage 2), and download.php (hidden iframe trigger).
The silently delivered payload is a ScreenConnect client installer (ScreenConnect.ClientSetup.msi), executed via msiexec with no visible UI. Once installed, the client beacons to a self-hosted ScreenConnect relay at cloud.zistopstoabetterlife.com over TCP port 8041, establishing persistent operator control. Additional second-stage payloads are staged from GitHub under the actor account 'creativebobo' (repos creativebobo/ceoexe and creativebobo/ceo), including microsoftceo.exe and ceo.msi. The kit customizes payload filenames to match victim business context (e.g., CapraAssetManagementInc.vbs) to increase legitimacy, and newer kit builds embed a Cloudflare telemetry token (fcfd0b3135e24171980eef5488a4927b) along with IP filtering and mobile-device detection to evade analysis and constrain delivery to intended targets.
For defense evasion and anti-forensics, the kit deploys heavily obfuscated batch scripts that self-delete after execution to remove traces. Because the RAT is a signed, legitimate ConnectWise binary, traditional signature-based AV is largely ineffective; detection relies on behavioral signals — msiexec spawning from temporary directories, unexpected ScreenConnect installations, and outbound connections to non-standard relay port 8041. Attribution is assessed at medium confidence to a Brazilian threat actor based on Sao Paulo-tied hosting (177.154.191.148) and Brazilian nameserver infrastructure (c3po3090.com.br); the actor handle itself remains unidentified. A BeaconBeagle lookup of 177.154.191.148 and the C2 domain returned no indexed Cobalt Strike/other-framework beacon, consistent with the use of ScreenConnect rather than a conventional C2 framework.
MITRE ATT&CK techniques used in TL-2026-0629
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Initial Access
T1189 Drive-by Compromise; T1566 Phishing
stealth
T1218 System Binary Proxy Execution
Command and Control
T1219 Remote Access Tools; T1571 Non-Standard Port
Persistence
T1543 Create or Modify System Process
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities
Reconnaissance
Affected products and versions in RatPressto Phishing Kit
- ConnectWise — ScreenConnect (remote support client)
Vulnerable versions: Abused as RAT — legitimate signed client, not a product vulnerability - WordPress — WordPress (self-hosted, exposed /wp-admin)
Vulnerable versions: Compromised sites used as phishing hosts
Remediation for RatPressto Phishing Kit
Immediate actions
- Block outbound TCP/8041 to cloud.zistopstoabetterlife.com and the listed actor IPs (177.154.191.148, 84.32.41.64) at the perimeter
- Block/sinkhole the phishing and C2 domains and quarantine emails impersonating Adobe Document Cloud file-sharing notifications
- Hunt for unauthorized ConnectWise ScreenConnect client installations and msiexec executions from temp/Downloads directories
- Block downloads of ScreenConnect.ClientSetup.msi, microsoftceo.exe, ceo.msi from non-approved sources
Workarounds
- Restrict or monitor egress to known ScreenConnect relay ports; alert on connections to non-corporate ScreenConnect instances
- Audit and lock down externally exposed WordPress /wp-admin panels (MFA, IP allowlist, plugin patching)
Longer-term hardening
- Application-control/allowlisting to restrict execution of remote-support tooling (ScreenConnect) to approved IT relays only
- Deploy EDR with behavioral detection for legitimate-tool abuse (RMM/RAT) and self-deleting batch scripts
- User awareness training on fake document-sharing lures; enforce DMARC/DKIM/SPF and link rewriting
Timeline of RatPressto Phishing Kit
- As of 2026-05-29, RatPressto remains ACTIVE: Fortra FIRE reported it just one day prior as an ongoing, reusable phishing kit abusing ConnectWise ScreenConnect, with no takedown, sinkhole, or arrest and an unidentified Brazilian actor still at large. The broader ScreenConnect/RMM-abuse trend is surging in 2026, and as legitimate-binary abuse (no CVE) the threat class stays fully viable.
- Threat ingested into Threadlinqs Intelligence pipeline (TL-2026-0629) for full analysis, simulation, and detection coverage.
- BeaconBeagle lookup of 177.154.191.148 and cloud.zistopstoabetterlife.com returns no indexed framework beacon, consistent with ScreenConnect (RMM) abuse rather than a conventional C2 framework.
- Public reporting by Cyber Security News and GBHackers details the fake Adobe Document Cloud lure, hidden-iframe delivery, and silent ScreenConnect installation.
- Self-hosted ScreenConnect C2 relay identified at cloud.zistopstoabetterlife.com over TCP port 8041; GitHub account 'creativebobo' observed staging second-stage payloads.
- Campaign assessed with medium confidence to a Brazilian threat actor based on Sao Paulo-tied hosting (177.154.191.148) and Brazilian nameserver infrastructure (c3po3090.com.br).
- Fortra's FIRE team identifies the reusable 'RatPressto' phishing kit abusing ConnectWise ScreenConnect against financial organizations.
Sources cited for RatPressto Phishing Kit
- Hackers Use Fake Adobe Document Cloud Pages to Deliver ScreenConnect Malware
- Fake Adobe Document Cloud Pages Spread ScreenConnect Malware
- Fortra FIRE Team — RatPressto Phishing Kit Analysis
- ConnectWise ScreenConnect (legitimate remote support tool abused as RAT)
- GitHub payload-staging account creativebobo (repo: ceoexe)
- GitHub payload-staging account creativebobo (repo: ceo)
Detection coverage for TL-2026-0629
As of 2026-05-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0629 across Splunk SPL, Microsoft KQL and Sigma, covering 26 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.