Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-04 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access (SMOKE#SCREEN)

Summary

Securonix disclosed details of an active, multi-wave campaign codenamed SMOKE#SCREEN that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to deploy ConnectWise ScreenConnect for persistent remote access.

Details

The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all pointing to a live WsgiDAV-based staging server. Successful attacks culminate with a ScreenConnect agent installed and beaconing to attacker-controlled relay servers. The campaign is relevant to the Acsc's guidance on social engineering and the Essential Eight's application control and patching requirements. The use of fake software updates as lures exploits user trust in established software vendors and underscores the importance of verifying software update sources.

Sources