Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access (SMOKE#SCREEN)
Summary
Securonix disclosed details of an active, multi-wave campaign codenamed SMOKE#SCREEN that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to deploy ConnectWise ScreenConnect for persistent remote access.
Details
The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all pointing to a live WsgiDAV-based staging server. Successful attacks culminate with a ScreenConnect agent installed and beaconing to attacker-controlled relay servers. The campaign is relevant to the Acsc's guidance on social engineering and the Essential Eight's application control and patching requirements. The use of fake software updates as lures exploits user trust in established software vendors and underscores the importance of verifying software update sources.
Sources
- The Hacker News
- raw/digests/Cyber-Digest-2026-08-05