Securonix researchers have identified an active campaign distributing ConnectWise ScreenConnect through fake software updates impersonating Adobe and Zoom. The operation, tracked as SMOKE#SCREEN, uses social engineering to trick users into downloading malicious installers.
The attack sequence follows a standard pattern. Victims receive messages claiming Adobe Reader, Adobe Acrobat, or Zoom require urgent updates. Links direct to convincing replica pages where users download what appears legitimate software. Instead, the installers deploy ConnectWise ScreenConnect, a legitimate RMM tool repurposed for persistent unauthorized access.
ConnectWise ScreenConnect enables remote desktop control, file transfer, and system administration capabilities. Once installed, threat actors maintain persistent access to compromised machines without user knowledge. The RMM platform's legitimate purpose in IT environments makes detection difficult. Defenders struggle to distinguish authorized use from malicious deployment.
The campaign distributes updates across multiple waves, suggesting ongoing refinement and testing. Attackers impersonate trusted brands with high user recognition. Adobe and Zoom updates are frequent enough that users expect notifications without suspicion.
Organizations face two distinct risks. End users downloading these fake installers expose corporate networks to unauthorized remote access. Attackers can move laterally once inside, accessing sensitive files, credentials, and systems. Second, IT teams managing legitimate RMM deployments must now scrutinize their ScreenConnect installations to confirm authorization.
Mitigation requires user awareness training emphasizing direct download verification. Users should obtain updates only from official vendor websites or in-app update mechanisms, never from email links or external pages. Organizations should implement application whitelisting to restrict RMM tool execution. Network monitoring should flag unexpected ScreenConnect connections originating from non-IT infrastructure.
The SMOKE#SCREEN campaign demonstrates how attackers weaponize trusted software platforms. Legitimate tools become attack vectors when
