All incidents

SMOKE#SCREEN campaign abuses ScreenConnect RMM via fake Zoom and Adobe updates

incidentopenAug 4, 2026 — Aug 7, 2026
SMOKE#SCREEN campaign abuses ScreenConnect RMM via fake Zoom and Adobe updates

THE SMOKE#SCREEN campaign has been observed abusing the legitimate ScreenConnect remote management tool by disguising malicious updates as fake Zoom and Adobe installers, according to Securonix research.

Victims receive phishing messages that lure them into clicking what appears to be a software update, which then drops a payload that installs a signed ScreenConnect agent for persistent remote access.

Researchers note that the campaign does not rely on a published CVE but instead uses multi‑stage droppers written in VBScript and .NET executables, as detailed in a recent analysis.

These droppers retrieve the final ScreenConnect payload from relay servers hosted on trusted platforms such as Cloudflare Tunnel and Dropbox, abiding by legitimate code‑signing certificates to bypass many endpoint controls.

Securonix analysis shows the operation consists of fifteen distinct payloads organised across five kill chains and supported by three relay servers, according to SecurityAffairs reporting.

Each chain employs different lures, ranging from business‑document pretences to system‑maintenance notices, allowing the attackers to adapt quickly to defensive measures.

Activity was first detected on 4 August 2026 and continued through 7 August 2026, affecting Windows and macOS users without any identified threat‑actor group claiming responsibility, as noted in Dark Reading coverage.

The tactics have shifted from overt attempts to disable security software toward a stealthier approach that leverages legitimate hosting services to evade detection.

Defenders should treat any unexpected appearance of ScreenConnect as suspicious and monitor for tampering with Windows Defender or other security tools.

Enforcing strict User Account Control settings, enabling behavioural‑based detection, and educating users to recognise unsolicited update prompts are essential steps.

Additionally, blocking known malicious domains associated with the relay servers and reviewing outbound traffic to Cloudflare and Dropbox can help prevent further compromise.

Intelligence briefing updated Aug 7, 2026

Root sourcewww.securonix.com
Timeline Coverage

Swipe to explore timeline