SMOKE#SCREEN Campaign - Fake Adobe/Zoom Updates Deploying ScreenConnect
First seen Aug 5, 2026 · Updated Aug 5, 2026
Securonix Threat Labs identified an active, multi-wave social engineering campaign dubbed SMOKE#SCREEN that uses fake Adobe and Zoom update prompts, fraudulent document review notices, and system maintenance lures to trick victims into installing ConnectWise ScreenConnect. Once installed, the legitimate RMM tool grants attackers persistent, stealthy remote access to compromised endpoints, bypassing many traditional malware detection controls due to ScreenConnect's legitimate code signing.
Technical Analysis
The campaign relies on trojanized installer lures mimicking legitimate Adobe and Zoom update notifications, alongside fake business document review pages and system utility prompts, to socially engineer users into executing a ScreenConnect installer package. Because ScreenConnect is a signed, legitimate RMM tool, its deployment often evades signature-based antivirus and endpoint detection, allowing attackers to establish long-term, low-noise remote access channels for follow-on activity such as credential harvesting, lateral movement, or secondary payload delivery. The multi-wave nature of the campaign suggests iterative infrastructure rotation and lure refinement to sustain effectiveness against user awareness and email/web filtering. No specific CVE is exploited; this is a pure social-engineering and living-off-trusted-tools (LOTL/RMM abuse) technique rather than a software vulnerability exploit. Any endpoint running AI agent frameworks, orchestration tools, or RAG pipelines that becomes compromised via this ScreenConnect foothold is at risk of API key, credential, and configuration exfiltration, potentially enabling attackers to hijack agent tool-use permissions or pivot into connected cloud/AI infrastructure.
Affected Systems
Windows endpoints where users download and execute unsolicited software update installers; environments lacking application allow-listing or RMM tool restrictions; organizations without email/web filtering for fake update lures
Indicators of Compromise
- ScreenConnect installer executables distributed via fake Adobe/Zoom update pages (specific hashes/domains not disclosed in source)
- Lure domains impersonating Adobe and Zoom update portals (not specified)
- Fake business document review/system maintenance utility pages (not specified)
Remediation Steps
- 1
Restrict RMM Tool Usage
Implement application allow-listing to block unauthorized installation of RMM tools like ScreenConnect unless explicitly approved by IT.
- 2
User Awareness Training
Educate employees to avoid downloading software updates from email links or pop-ups; direct them to verify updates through official vendor channels only.
- 3
Network and Endpoint Monitoring
Monitor for unexpected installation or execution of ScreenConnect or other RMM binaries, especially from non-IT-approved sources or unusual parent processes.
- 4
Email and Web Filtering
Deploy filtering solutions to detect and block phishing lures themed around software update notifications.
- 5
Credential and API Key Rotation
For any endpoint suspected of compromise, rotate all stored credentials and API keys, including those used by AI agent or automation frameworks, to prevent downstream exploitation.
- 6
Least Privilege for Agent Hosts
Ensure hosts running AI agents or orchestration tools have minimal standing privileges and segmented network access to limit blast radius if compromised via this vector.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.