Reading view

There are new articles available, click to refresh the page.

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices.

Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a legitimate Adobe webpage, before convincing victims to download malicious software disguised as an Adobe Reader update.

Rather than deploying conventional malware, the attackers installed rogue instances of ScreenConnect, legitimate remote monitoring and management (RMM) software, giving them continued remote access to compromised endpoints.

Fake browser makes phishing harder to spot

BiTB attacks create a fake browser window inside a webpage using HTML, CSS and JavaScript. The window can replicate familiar features including an address bar, padlock and legitimate-looking URL, making traditional advice such as checking the web address less effective.

In the first attack, detected on 25 August, a victim clicked a link in a phishing email and was taken to a fake CAPTCHA page. They were subsequently presented with blurred documents and told they needed to download Adobe PDF Reader to view them.

The fake browser page appeared to show Adobe’s legitimate get.adobe.com address. However, the supposed Reader installer was actually ScreenConnect.

Once installed, the attackers deployed two rogue ScreenConnect clients, providing redundant routes for maintaining access. They then executed HideCursor.exe, a defence-evasion tool designed to conceal on-screen activity. Huntress intervened before the attack could progress further.

Second attack follows same playbook

Huntress identified another incident on 31 August involving the same Adobe Reader lure.

This time, the victim interacted with a malicious link delivered through AT&T Office@Hand, a legitimate communications service powered by RingCentral. The attackers again disguised ScreenConnect as an Adobe Reader update and installed two unauthorised instances.

The second ScreenConnect session was used to execute another defence-evasion binary, HideUL.exe. Microsoft Defender detected part of the activity, but the rogue ScreenConnect client still completed its installation before Huntress shut down the attack.

Legitimate tools remain attractive to attackers

The attacks demonstrate how threat actors can combine familiar phishing techniques with trusted software to make malicious activity harder to identify.

RMM abuse is a growing problem. Huntress’ 2026 Cyber Threat Report found RMM abuse increased 277% year on year and appeared in nearly a quarter of the incidents investigated by the company.

Huntress recommends organisations restrict who can install remote management tools, maintain an approved inventory of RMM software and monitor for new or unauthorised ScreenConnect clients. Employees should also be wary of unexpected software updates or file-viewing prompts, even when a webpage appears to display a legitimate address.

Read the full research here. 

The post Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools appeared first on IT Security Guru.

Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers

Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals.

The incident affected customer information associated with Manchester Airport, London Stansted and East Midlands Airport. Data connected to car park, lounge and Fast Track bookings, as well as airport Wi-Fi registrations, was reportedly accessed.

Email addresses, phone numbers, postcodes and vehicle registration details are among the information affected. However, payment information was not compromised, while airport operations, passenger safety and aviation security were unaffected.

While this limits the immediate operational impact, security experts warn that the combination of information exposed could prove particularly useful for targeted phishing, impersonation and social engineering.

Stolen data could make scams much harder to spot

Simon Pamplin, CTO at Certes, said the fact that operations were unaffected should not distract from the significance of the data exposure.

“Around 8.7 million customer records have reportedly been accessed, including email addresses, phone numbers, postcodes and vehicle registration details. Individually these may appear relatively innocuous, but together they create a detailed dataset that can be extremely useful for targeted phishing, impersonation and social engineering.”

The context surrounding the information could make it especially valuable. Criminals could potentially create fraudulent parking notices, travel communications or airport-related messages containing enough genuine information to appear legitimate.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, described the combination of information as a “precise targeting profile” for criminals.

“Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,” he said.

Carole Reeves, Director of Security Operations at ANS, agreed that the absence of payment information should not lead customers to underestimate the risk.

“Attackers do not always need financial credentials from the initial breach. They can use the information they have to impersonate a trusted organisation and manipulate someone into revealing further personal or financial details.”

Aviation sector faces growing cyber pressure

Graeme Stewart, Head of Public Sector at Check Point Software, said the incident should serve as a warning to the wider aviation industry.

“The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised,” he said.

Knowledge of a customer’s relationship with an airport could potentially be used to create fake parking refunds, Fast Track problems or communications about the breach itself.

“Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake,” Stewart added.

Complex airport ecosystems create additional risks

The attack also raises questions about the complex technology ecosystems supporting modern airports.

Nathan Davies-Webb, Principal Consultant at Acumen Cyber, said airport groups sit at the centre of numerous booking, parking, loyalty, payment and internet connectivity services, many of which can be operated by subsidiaries or third-party suppliers.

“That’s a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously.”

Davies-Webb also highlighted the speed of MAG’s response, with public disclosure roughly 48 hours after it became aware of the incident.

“Either way, it’s a better disclosure posture than we’ve seen from organisations involved in some comparable incidents, and MAG will probably benefit from having been quick and open here,” he said.

Tim Williams, CEO at Quod Orbis, also pointed to the importance of visibility beyond an organisation’s core systems.

“While the systems targeted were car parking, lounge bookings and WiFi sign-ups, they were not responsible for flight operations; they formed part of the wider digital environment through which customers interact within the airport,” Williams said.

He argued that security teams need visibility across systems, applications and third-party services so that risks can be identified before they become incidents.

“Rapid response can contain an incident, but having visibility across the wider technology and third-party ecosystem can help organisations identify potential weaknesses earlier, understand their exposure and strengthen their defences before an incident occurs.”

Knowing what data was accessed matters

The breach also highlights the importance of understanding exactly what information has been exposed once an attacker gains access.

Jerry Caviston, CEO at Archive360, said good data governance can provide organisations with the traceability needed during an incident.

“Having good data governance is like having CCTV footage of what data was touched and when,” he said.

Maintaining an event audit history can help organisations trace compromised information back to its original source and provide affected customers with clearer information about the risks they face.

Pamplin argues organisations should go further by attaching security directly to the data.

“We have to work on the assumption that systems will eventually be accessed. The objective should be that when this happens, sensitive data remains encrypted and unusable outside its authorised context,” he said.

“If an attacker can steal information but cannot read or exploit it, the value of the breach changes fundamentally.”

Customers should prepare for follow-on attacks

The immediate concern for affected customers is what criminals could do with the information next.

Jamie Akhtar, CEO and Co-Founder of CyberSmart, advised customers to be particularly cautious of unexpected emails, calls or texts claiming to relate to airport or travel services.

“Avoid clicking links or sharing personal information in unsolicited messages and, where possible, verify communications independently through an organisation’s official website or app,” he said.

Shankar Haridas, UK Business Head at ManageEngine, warned that the original breach could be followed by attacks designed to exploit customers’ trust in MAG.

“A breach like this doesn’t end when the data is taken. A flood of cloaked attacks, dressed up in the airport’s name is next,” he said.

“With 8.7 million email addresses, phone numbers and postcodes now in criminal hands, every ‘confirm your booking’ or ‘update your car park payment’ message must be questioned.”

Brian Higgins, Security Specialist at Comparitech, added that AI is making it easier for criminals to aggregate breached information and find new ways of monetising it.

“As AI makes data aggregation swift and easy, consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways,” he said.

For those potentially affected, the consequences of the MAG cyberattack may therefore continue long after the initial incident has been contained. Emails or messages referencing airport parking, lounge access, Fast Track services or travel details could contain genuine personal information, making the next wave of scams considerably harder to recognise.

The post Manchester Airports Group Cyberattack Exposes Data of 8.7 Million Customers appeared first on IT Security Guru.

Iran-Linked Hackers Blamed for UK Energy Cyberattack

A cyberattack reportedly linked to Iran forced a small UK energy generator offline for four days, raising fresh concerns about the security of the country’s critical infrastructure and smaller operators that may sit outside existing regulatory thresholds.

The UK government has confirmed that a small-scale generator was affected by a cyber incident in July. It stressed that the facility represented a tiny proportion of overall generation capacity and that the wider UK energy system was never at risk.

The government has not publicly attributed the attack or named the affected site. However, reports have linked the incident to hackers affiliated with Iran.

Following the incident, the Department for Energy Security and Net Zero (DESNZ) and National Cyber Security Centre (NCSC) have been engaging with energy companies over the cyber threat facing the sector.

Small target, bigger security questions

While the facility itself was small, cybersecurity experts warn that its size should not distract from the fact that a cyber incident reportedly caused several days of operational disruption.

Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said attackers are unlikely to care whether an operator meets the threshold to be considered critical infrastructure.

“If it can be disrupted, it can be targeted,” Patel said. “The significance isn’t the size of the facility, but that a cyberattack turned into four days of real-world operational disruption.”

Patel said the incident raises questions about whether smaller operators have sufficient monitoring, containment and recovery capabilities.

“There is also a potential visibility gap. If smaller energy operators fall outside mandatory cyber-reporting thresholds, we risk underestimating how frequently this part of our infrastructure is being targeted or successfully compromised.”

Attribution remains uncertain

Despite reports linking the incident to Iran, Cian Heasley, Principal Consultant at Acumen Cyber, cautioned against concluding before further evidence emerges.

“Attribution for the incident is by no means concrete; the Iran link originates from press reporting while the UK government has declined to attribute blame or name the site affected,” Heasley said.

He argued that the more important lesson for the energy sector is what the incident demonstrates about the potential vulnerability of smaller energy assets.

“The significance of this incident lies in the precedent rather than the impact. A successful, if limited, intrusion into a power-generating asset demonstrates intent and a degree of capability against British energy infrastructure.”

Heasley said operators should focus on OT security fundamentals, including removing industrial controllers from direct internet exposure, strengthening credential management, separating IT and OT environments, and testing manual fallback and recovery procedures.

Graeme Stewart, head of public sector at Check Point, said the incident should concern organizations responsible for keeping essential services running.

“The fact that this was a relatively small generator and the wider grid was unaffected does not remove the threat,” Stewart said. “The far more serious point is what the attackers appear to have demonstrated: an ability to get inside UK energy infrastructure and stop it working.”

He warned that the bigger question is what happens if a future target is larger or more deeply connected to essential services such as electricity, water, transport, or communications.

“We cannot build our resilience around the assumption that every attacker will be stopped at the door,” he said. “Operators of essential services need to know exactly how they keep functioning when systems are compromised, how quickly an attack can be contained and how they recover without allowing disruption to spread.”

The distributed energy system creates new risks

Martin Riley, Chief Technology Officer at Bridewell, said the small size of the facility is precisely why the incident deserves attention.

“The reported attack on a UK gas-fired peaker plant should not be dismissed because the site was small. It should be studied because the site was small,” Riley said.

The UK’s energy system increasingly depends on smaller generators, renewable energy assets and battery storage systems. Many are unmanned and remotely operated.

Riley warned that capacity thresholds mean some smaller operators can fall outside formal cybersecurity regimes even as their collective importance to the energy system grows.

“In an energy system that is deliberately becoming distributed, reliant on thousands of smaller, unmanned, remotely operated generators, secure by design and defence in depth cannot remain conference slideware.”

Neena Sharma, Cybersecurity Expert at Filigran, made a similar point, arguing that critical infrastructure risk is becoming increasingly distributed.

“Critical infrastructure risk isn’t concentrated at the ‘crown jewel’ substations anymore, it’s distributed across hundreds of smaller, less-monitored assets that scale with the energy transition,” Sharma said.

Weak credentials remain a concern

The exact attack path used against the UK generator has not been disclosed.

However, Sai Molige, Senior Manager of Threat Hunting at Forescout, pointed to a familiar weakness seen in attacks against industrial environments.

“Two countries and two sectors faced the same underlying condition: a controller is reachable from the internet and protected by weak, default, or unchanged credentials,” Molige said.

He argued that one of the continuing challenges for operators is translating broad security warnings into an accurate understanding of whether their own environments contain vulnerable or exposed technology.

Supply Chain Risk Adds Another Layer

The incident also comes as the UK looks to tighten security across energy supply chains, where dependence on individual suppliers and technologies can create additional risks.

Jamie Akhtar, CEO and Co-founder of CyberSmart, said supply chain risk is not simply about whether an individual supplier can be compromised.

“If one vendor, country or narrow group of manufacturers underpins equipment that operators cannot quickly replace, that dependency can become a national-security issue,” Akhtar said.

This can be particularly difficult in operational technology environments, where equipment may remain in use for decades and replacing it can require complex integration work.

Akhtar said operators need to consider whether a supplier creates an unacceptable security exposure, whether it can realistically be replaced and whether removing it could create a greater short-term risk to operations.

“The strategic aim should be resilience, not a compliance exercise or a change of logo on the equipment,” he added. “Operators need enough diversity, control and recovery capability to keep essential services running if a supplier is compromised, unavailable or deemed too risky to trust.”

Resilience becomes the priority

The incident comes as the UK looks to strengthen cyber resilience across its energy sector and address risks within increasingly complex supply chains.

For Patel, the central lesson is that organizations cannot judge resilience solely by whether an attacker successfully gains access.

“The real measure of cyber resilience is no longer simply whether you can prevent an intrusion,” he said. “It’s whether you can contain one quickly enough that a cyber incident doesn’t become an operational crisis.”

With the wider grid unaffected, the July incident was limited in impact, but the disruption provides a timely warning that smaller assets can still present attractive targets and that cyber resilience needs to extend beyond the largest operators in the UK’s energy infrastructure.

The post Iran-Linked Hackers Blamed for UK Energy Cyberattack appeared first on IT Security Guru.

❌