# RatPressto Phishing Kit — Fake Adobe Document Cloud Pages Deliver ConnectWise ScreenConnect RAT

> Fortra's FIRE team identified 'RatPressto', a reusable private phishing kit targeting financial organizations with fake Adobe Document Cloud 'Download Complete' pages hosted on compromised WordPress sites. A hidden iframe silently triggers a ConnectWise ScreenConnect installer, abusing the legitimate remote support tool as a RAT for full remote control. The operation is assessed with medium confidence to a Brazilian threat actor based on Sao Paulo-tied infrastructure.

- **Published:** 2026-05-29T00:00:00Z
- **Last reviewed:** 2026-05-29T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0629
- **ID:** TL-2026-0629
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 26 (full data via the Threadlinqs MCP server — Purple tier)

## Description

RatPressto is a reusable, privately distributed phishing kit documented by Fortra's Intelligence and Research Experts (FIRE) team and publicly reported on 2026-05-29. The campaign primarily targets financial organizations and abuses the legitimate ConnectWise ScreenConnect remote support client as a remote access trojan (RAT), giving operators full interactive control of compromised endpoints while blending into environments where remote-support tooling is common.

The exploit chain begins with phishing emails that impersonate Adobe Document Cloud file-sharing notifications, claiming a confidential project document has been shared. Victims who click the 'View File'/download link are redirected to compromised WordPress sites (frequently with publicly exposed /wp-admin panels) that host a convincing fake Adobe 'Download Complete' page. The page renders Adobe branding and a loading animation purely as a distraction: while the victim reads on-screen instructions to open the file, a hidden iframe (download.php) has already silently fetched the payload. The delivery flow chains download.html (stage 1 lure), complete.php (stage 2), and download.php (hidden iframe trigger).

The silently delivered payload is a ScreenConnect client installer (ScreenConnect.ClientSetup.msi), executed via msiexec with no visible UI. Once installed, the client beacons to a self-hosted ScreenConnect relay at cloud.zistopstoabetterlife.com over TCP port 8041, establishing persistent operator control. Additional second-stage payloads are staged from GitHub under the actor account 'creativebobo' (repos creativebobo/ceoexe and creativebobo/ceo), including microsoftceo.exe and ceo.msi. The kit customizes payload filenames to match victim business context (e.g., CapraAssetManagementInc.vbs) to increase legitimacy, and newer kit builds embed a Cloudflare telemetry token (fcfd0b3135e24171980eef5488a4927b) along with IP filtering and mobile-device detection to evade analysis and constrain delivery to intended targets.

For defense evasion and anti-forensics, the kit deploys heavily obfuscated batch scripts that self-delete after execution to remove traces. Because the RAT is a signed, legitimate ConnectWise binary, traditional signature-based AV is largely ineffective; detection relies on behavioral signals — msiexec spawning from temporary directories, unexpected ScreenConnect installations, and outbound connections to non-standard relay port 8041. Attribution is assessed at medium confidence to a Brazilian threat actor based on Sao Paulo-tied hosting (177.154.191.148) and Brazilian nameserver infrastructure (c3po3090.com.br); the actor handle itself remains unidentified. A BeaconBeagle lookup of 177.154.191.148 and the C2 domain returned no indexed Cobalt Strike/other-framework beacon, consistent with the use of ScreenConnect rather than a conventional C2 framework.

## MITRE ATT&CK

- T1584 Compromise Infrastructure
- T1608 Stage Capabilities
- T1583 Acquire Infrastructure
- T1566 Phishing
- T1189 Drive-by Compromise
- T1204 User Execution
- T1218 System Binary Proxy Execution
- T1059 Command and Scripting Interpreter
- T1543 Create or Modify System Process
- T1036 Masquerading
- T1070 Indicator Removal
- T1027 Obfuscated Files or Information
- T1219 Remote Access Tools
- T1571 Non-Standard Port
- T1592 Gather Victim Host Information

## Sources

- [Hackers Use Fake Adobe Document Cloud Pages to Deliver ScreenConnect Malware](https://cybersecuritynews.com/hackers-use-fake-adobe-document-cloud-pages/)
- [Fake Adobe Document Cloud Pages Spread ScreenConnect Malware](https://gbhackers.com/fake-adobe-document-cloud-pages/)
- [Fortra FIRE Team — RatPressto Phishing Kit Analysis](https://www.fortra.com/blog)
- [ConnectWise ScreenConnect (legitimate remote support tool abused as RAT)](https://www.connectwise.com/platform/unified-management/screenconnect)
- [GitHub payload-staging account creativebobo (repo: ceoexe)](https://github.com/creativebobo/ceoexe)
- [GitHub payload-staging account creativebobo (repo: ceo)](https://github.com/creativebobo/ceo)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0629
