THE Smoke#Screen cyberattack campaign leverages the legitimate ScreenConnect RMM tool through various social engineering tactics. Cybercriminals utilize lures related to Zoom and Adobe updates, business documents, and system maintenance to install ScreenConnect agents for persistent access. The campaign showcases advanced techniques, including rotating payloads and diverse psychological lures, to compromise Windows and macOS systems.
Securonix researchers traced the attack's evolution, highlighting weaknesses in security detection due to the legitimate nature of the software involved. Recommendations for defense include behavioral detection strategies and ensuring strict User Account Control (UAC) settings.