THE SMOKE#SCREEN campaign, tracked by Securonix, employs multi-wave phishing tactics to exploit remote management tools like ScreenConnect. Attackers lure victims, primarily Windows and macOS users, with fake software update notifications related to Zoom and Adobe, ultimately delivering a legitimate ConnectWise-signed ScreenConnect payload to gain remote access. The campaign has identified 15 payloads, 5 kill chains, and uses 3 relay servers, showcasing elaborate evasion tactics against endpoint detection.
Recommendations for protection include treating unexpected ScreenConnect installations as suspicious, monitoring for Defender tampering, and advising users on recognizing phishing attempts.