SMOKE#SCREEN campaign uses fake Adobe and Zoom updates to deliver malicious ScreenConnect
> cd .. / HUB_EDITORIALE
News

SMOKE#SCREEN campaign uses fake Adobe and Zoom updates to deliver malicious ScreenConnect

[2026-08-05] Author: Ing. Calogero Bono
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

Securonix Threat Research analysts have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management software. Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, along with a wide array of fraudulent business-related documents such as document review requests, system maintenance tools, and invoices, to convince victims to run malicious files. Those who fall for the ruse end up installing ConnectWise ScreenConnect, a legitimate RMM tool used by many IT teams for technical support, but also one of the most abused solutions in the cybercriminal underground because it often flies under the radar of security products.

Dangerous evolution of the threat

After installation, attackers can remotely access compromised devices, potentially stealing data, installing additional threats, or moving deeper into an organization's network. At first glance, SMOKE#SCREEN looks like a standard phishing campaign that installs a legitimate RMM to gain remote access. However, what makes it unique is how it evolved over time. Earlier versions focused on hiding malicious activity, while newer versions attempt to disable security protections and avoid detection by security software. The attackers also used trusted services like Dropbox and Cloudflare to deliver their files, making the activity harder to block. Victims have been observed on both Windows and macOS ecosystems.

Sponsored Protocol

A well-resourced and rapidly adapting threat actor

The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments. The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.

Sponsored Protocol

How to defend against the threat

To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting. It is crucial to be wary of messages that prompt unexpected installations, as seen with the fake Adobe and Zoom updates used in this campaign. The use of legitimate cloud services to host payloads makes the threat even harder to detect. This discovery comes at a time when cybersecurity news is frequent, but the uniqueness of SMOKE#SCREEN lies in its ability to evolve. According to experts, IT teams must adopt a proactive approach, monitoring outbound remote connections and utilizing endpoint detection and response solutions. For insights into related threats, you can read about the Claude global outage and how even legitimate services can be targeted. Additionally, the growing prevalence of attacks exploiting remote support software is a wake-up call for all organizations, as highlighted in Take-Two Moves Earnings Release, which shows how companies must pay attention to every aspect of their cybersecurity. The threat is real and requires constant vigilance, as also explained in Train Sim World 6 drops Xbox One and PS4, where device security is a central theme. For more defense strategies, refer to the guide on Security Focus.

Sponsored Protocol

Source: https://www.techradar.com/pro/security/hackers-use-fake-adobe-and-zoom-updates-to-load-malware-onto-victim-devices-heres-what-to-look-out-for

> share
Ing. Calogero Bono

> AUTHOR_EXTRACTED

Ing. Calogero Bono

Ingegnere informatico, fondatore di Meteora Web e Zenith OS. System administrator e progettista di piattaforme, app e CMS proprietari, con esperienza in sviluppo full-stack, marketing digitale ed ecosistema Google.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()