Technology News

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Researchers have uncovered a phishing operation that masquerades as legitimate software updates and installs Remote Monitoring and Management software to give attackers long‑term access.

Cybersecurity researchers have uncovered a sophisticated phishing operation that masquerades as legitimate software updates and maintenance tools to covertly install Remote Monitoring and Management (RMM) software on victim machines. The campaign, dubbed SMOKE#SCREEN by Securonix Threat, targets users through Adobe and Zoom update prompts, business document review requests, and generic system maintenance utilities.

The attackers craft emails that appear to come from Adobe or Zoom, urging recipients to download a patch or update. The attachments or links lead to a malicious installer that silently installs ConnectWise ScreenConnect, a legitimate RMM solution that can give attackers persistent remote access.

Researchers identified several waves of the campaign, each with slightly different messaging and file names. Early waves used Adobe Creative Cloud update themes; later waves shifted to Zoom update notifications and generic system maintenance.

The emails employ familiar branding, urgent language, and a sense of official authority to lower the recipients’ guard. Some messages even include a mock “Adobe update” screenshot or a Zoom logo to reinforce authenticity.

ConnectWise ScreenConnect is a widely used remote support platform that allows administrators to view, control, and manage endpoints. In the hands of attackers, it can be used to exfiltrate data, install additional malware, or maintain long‑term footholds.

Because ScreenConnect is legitimate, the malicious installer can bypass many security controls that flag unknown or malicious software. Once installed, the attacker can conduct reconnaissance, lateral movement, and data exfiltration.

Security teams should monitor for unusual outbound connections to known ScreenConnect domains, flag any unauthorized installations, and enforce least‑privilege principles on endpoints. Regular patching of Adobe and Zoom software can also reduce the window of opportunity for attackers.

Securonix released the threat intelligence report that identified the campaign’s patterns, file names, and distribution channels. Their analysis highlighted the use of legitimate RMM tools as a new stealth vector.

Users should avoid downloading software updates from unverified sources, verify the publisher’s digital signatures, and be cautious of emails that prompt immediate action. Multi‑factor authentication and endpoint detection and response solutions can help block the initial compromise.

The SMOKE#SCREEN campaign demonstrates how attackers can blend legitimate software and social engineering to bypass defenses. Vigilance and proactive monitoring are essential to protect against this evolving threat.

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have uncovered a sophisticated phishing operat…

Cybersecurity researchers have uncovered a sophisticated phishing operat…

Cybersecurity researchers have uncovered a sophisticated phishing operation that masquerades as legitimate software updates and maintenance tools to covertly install Remote Monitoring and Management (RMM) software on victim machines. The campaign, dubbed SMOKE#SCREEN by Securonix Threat, targets users through Adobe and Zoom update prompts, business document review requests, and generic system maintenance utilities.

The attackers craft emails that appear to come from Adobe or Zoom, urging recipients to download a patch or update. The attachments or links lead to a malicious installer that silently installs ConnectWise ScreenConnect, a legitimate RMM solution that can give attackers persistent remote access.

Researchers identified several waves of the campaign, each with slightly…

Researchers identified several waves of the campaign, each with slightly…

Researchers identified several waves of the campaign, each with slightly different messaging and file names. Early waves used Adobe Creative Cloud update themes; later waves shifted to Zoom update notifications and generic system maintenance.

The emails employ familiar branding, urgent language, and a sense of official authority to lower the recipients’ guard. Some messages even include a mock “Adobe update” screenshot or a Zoom logo to reinforce authenticity.

ConnectWise ScreenConnect is a widely used remote support platform that…

ConnectWise ScreenConnect is a widely used remote support platform that…

ConnectWise ScreenConnect is a widely used remote support platform that allows administrators to view, control, and manage endpoints. In the hands of attackers, it can be used to exfiltrate data, install additional malware, or maintain long‑term footholds.

Because ScreenConnect is legitimate, the malicious installer can bypass many security controls that flag unknown or malicious software. Once installed, the attacker can conduct reconnaissance, lateral movement, and data exfiltration.

Security teams should monitor for unusual outbound connections to known…

Security teams should monitor for unusual outbound connections to known…

Security teams should monitor for unusual outbound connections to known ScreenConnect domains, flag any unauthorized installations, and enforce least‑privilege principles on endpoints. Regular patching of Adobe and Zoom software can also reduce the window of opportunity for attackers.

Securonix released the threat intelligence report that identified the campaign’s patterns, file names, and distribution channels. Their analysis highlighted the use of legitimate RMM tools as a new stealth vector.

Users should avoid downloading software updates from unverified sources,…

Users should avoid downloading software updates from unverified sources,…

Users should avoid downloading software updates from unverified sources, verify the publisher’s digital signatures, and be cautious of emails that prompt immediate action. Multi‑factor authentication and endpoint detection and response solutions can help block the initial compromise.

The SMOKE#SCREEN campaign demonstrates how attackers can blend legitimate software and social engineering to bypass defenses. Vigilance and proactive monitoring are essential to protect against this evolving threat.