highPhishing

SMOKE#SCREEN Campaign - Fake Adobe/Zoom Updates Deploying ScreenConnect

First seen Aug 5, 2026 · Updated Aug 5, 2026

social-engineeringrmm-abusescreenconnectfake-updatesinitial-accessagent-relevant

Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.

Technical Analysis

The campaign relies on trojanized installer lures mimicking legitimate Adobe and Zoom update notifications, alongside fake business document review pages and system utility prompts, to socially engineer users into executing a ScreenConnect installer package. Because ScreenConnect is a signed, legitimate RMM tool, its deployment often evades signature-based antivirus and endpoint detection, allowing attackers to establish long-term, low-noise remote access channels for follow-on activity such as credential harvesting, lateral movement, or secondary payload delivery. The multi-wave nature of the campaign suggests iterative infrastructure rotation and lure refinement to sustain effectiveness against user awareness and email/web filtering. No specific CVE is exploited; this is a pure social-engineering and living-off-trusted-tools (LOTL/RMM abuse) technique rather than a software vulnerability exploit. Any endpoint running AI agent frameworks, orchestration tools, or RAG pipelines that becomes compromised via this ScreenConnect foothold is at risk of API key, credential, and configuration exfiltration, potentially enabling attackers to hijack agent tool-use permissions or pivot into connected cloud/AI infrastructure.

Affected Systems

Windows endpoints where users download and execute unsolicited software update installers; environments lacking application allow-listing or RMM tool restrictions; organizations without email/web filtering for fake update lures

Indicators of Compromise

  • ScreenConnect installer executables distributed via fake Adobe/Zoom update pages (specific hashes/domains not disclosed in source)
  • Lure domains impersonating Adobe and Zoom update portals (not specified)
  • Fake business document review/system maintenance utility pages (not specified)

Remediation Steps

  1. 1

    Restrict RMM Tool Usage

    Implement application allow-listing to block unauthorized installation of RMM tools like ScreenConnect unless explicitly approved by IT.

  2. 2

    User Awareness Training

    Educate employees to avoid downloading software updates from email links or pop-ups; direct them to verify updates through official vendor channels only.

  3. 3

    Network and Endpoint Monitoring

    Monitor for unexpected installation or execution of ScreenConnect or other RMM binaries, especially from non-IT-approved sources or unusual parent processes.

  4. 4

    Email and Web Filtering

    Deploy filtering solutions to detect and block phishing lures themed around software update notifications.

  5. 5

    Credential and API Key Rotation

    For any endpoint suspected of compromise, rotate all stored credentials and API keys, including those used by AI agent or automation frameworks, to prevent downstream exploitation.

  6. 6

    Least Privilege for Agent Hosts

    Ensure hosts running AI agents or orchestration tools have minimal standing privileges and segmented network access to limit blast radius if compromised via this vector.

Industries Most Exposed

cross-industryenterprise ITmanaged service providersgeneral business sector

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.