Securonix Threat Research analysts have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management software. Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, along with a wide array of fraudulent business-related documents such as document review requests, system maintenance tools, and invoices, to convince victims to run malicious files. Those who fall for the ruse end up installing ConnectWise ScreenConnect, a legitimate RMM tool used by many IT teams for technical support, but also one of the most abused solutions in the cybercriminal underground because it often flies under the radar of security products.
Dangerous evolution of the threat
After installation, attackers can remotely access compromised devices, potentially stealing data, installing additional threats, or moving deeper into an organization's network. At first glance, SMOKE#SCREEN looks like a standard phishing campaign that installs a legitimate RMM to gain remote access. However, what makes it unique is how it evolved over time. Earlier versions focused on hiding malicious activity, while newer versions attempt to disable security protections and avoid detection by security software. The attackers also used trusted services like Dropbox and Cloudflare to deliver their files, making the activity harder to block. Victims have been observed on both Windows and macOS ecosystems.
Sponsored Protocol
A well-resourced and rapidly adapting threat actor
The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments. The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.
Sponsored Protocol
How to defend against the threat
To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting. It is crucial to be wary of messages that prompt unexpected installations, as seen with the fake Adobe and Zoom updates used in this campaign. The use of legitimate cloud services to host payloads makes the threat even harder to detect. This discovery comes at a time when cybersecurity news is frequent, but the uniqueness of SMOKE#SCREEN lies in its ability to evolve. According to experts, IT teams must adopt a proactive approach, monitoring outbound remote connections and utilizing endpoint detection and response solutions. For insights into related threats, you can read about the Claude global outage and how even legitimate services can be targeted. Additionally, the growing prevalence of attacks exploiting remote support software is a wake-up call for all organizations, as highlighted in Take-Two Moves Earnings Release, which shows how companies must pay attention to every aspect of their cybersecurity. The threat is real and requires constant vigilance, as also explained in Train Sim World 6 drops Xbox One and PS4, where device security is a central theme. For more defense strategies, refer to the guide on Security Focus.
Sponsored Protocol