securityonline.info 8/7/2026, 8:31:11 AM · external

SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access

SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access
Developing story incident 3 articles tracked
SMOKE#SCREEN campaign abuses ScreenConnect RMM via fake Zoom and Adobe updates
CyberSIXT Evidence Panel
Primary Source securonix.com

THE SMOKE#SCREEN campaign, tracked by Securonix, employs multi-wave phishing tactics to exploit remote management tools like ScreenConnect. Attackers lure victims, primarily Windows and macOS users, with fake software update notifications related to Zoom and Adobe, ultimately delivering a legitimate ConnectWise-signed ScreenConnect payload to gain remote access. The campaign has identified 15 payloads, 5 kill chains, and uses 3 relay servers, showcasing elaborate evasion tactics against endpoint detection.

Recommendations for protection include treating unexpected ScreenConnect installations as suspicious, monitoring for Defender tampering, and advising users on recognizing phishing attempts.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline