securityaffairs.com 8/5/2026, 6:09:35 AM · external

Attackers Abuse Fake Zoom Updates to Deploy ScreenConnect RMM

Attackers Abuse Fake Zoom Updates to Deploy ScreenConnect RMM
CyberSIXT Evidence Panel
Primary Source securonix.com

THE SMOKE#SCREEN campaign is a sophisticated cyber threat utilizing social engineering to install ScreenConnect, a legitimate remote monitoring tool, on victim machines masquerading as fake Zoom updates and other benign software notices. Attackers gain persistent remote access by leveraging a variety of methods including VBScript droppers, .NET executables, and customized HTML phishing pages.

Securonix's research indicates that the campaign includes innovative techniques to avoid detection, such as exploiting trusted hosting platforms like Dropbox and Cloudflare. This strategy has shifted over time from aggressive tactics aimed at disrupting security measures to a more stealthy approach, indicating rapid adaptation to countermeasures. The final payloads are authenticated via valid certificates, enabling attackers to blend in with legitimate IT activity. Researchers emphasize behavior-based detection methods and the need to monitor for unauthorized RMM tool use.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline