THE SMOKE#SCREEN campaign is a sophisticated cyber threat utilizing social engineering to install ScreenConnect, a legitimate remote monitoring tool, on victim machines masquerading as fake Zoom updates and other benign software notices. Attackers gain persistent remote access by leveraging a variety of methods including VBScript droppers, .NET executables, and customized HTML phishing pages.
Securonix's research indicates that the campaign includes innovative techniques to avoid detection, such as exploiting trusted hosting platforms like Dropbox and Cloudflare. This strategy has shifted over time from aggressive tactics aimed at disrupting security measures to a more stealthy approach, indicating rapid adaptation to countermeasures. The final payloads are authenticated via valid certificates, enabling attackers to blend in with legitimate IT activity. Researchers emphasize behavior-based detection methods and the need to monitor for unauthorized RMM tool use.