Fake Adobe & Zoom Updates Deploy Persistent RMM Backdoors
Attackers use fake software updates to install ScreenConnect for persistent remote access. Security teams should monitor for unauthorized RMM deployments.
TL;DR
- Cybercriminals are using fake Adobe and Zoom update lures to deploy ScreenConnect RMM tools
- The SMOKE#SCREEN campaign uses business-themed social engineering tactics
- Targets receive malicious payloads disguised as document reviews and system utilities
- ScreenConnect installations enable persistent remote access and monitoring
- Organizations should audit for unauthorized RMM software and suspicious update patterns
Security researchers have uncovered an active multi-stage attack campaign leveraging fake software updates to gain persistent remote access to target systems. The operation, dubbed SMOKE#SCREEN by Securonix Threat Labs, disguises malicious payloads as legitimate Adobe and Zoom software updates.
Once executed, these deceptive installers deploy ConnectWise ScreenConnect remote monitoring and management tools, giving attackers long-term access to compromised environments. The campaign demonstrates sophisticated social engineering techniques that exploit user trust in commonly used business applications.
This attack highlights the critical importance of verifying software updates through official channels and maintaining strict controls over remote access tools within enterprise environments.
Attack Vector and Social Engineering Tactics
- Attackers use convincing fake update notifications for widely trusted software like Adobe Reader and Zoom
- Lures include business document review requests and system maintenance utility downloads
- Initial access is gained through phishing emails containing malicious links or attachments
- Payloads are designed to appear as legitimate software installation processes
- Multi-wave delivery increases chances of successful compromise across different target profiles
Technical Impact and Defensive Recommendations
- ScreenConnect deployment enables persistent remote access, keylogging, and file transfer capabilities
- RMM tools can operate with elevated privileges, making detection and removal challenging
- Organizations should implement application whitelisting to prevent unauthorized software installations
- Network monitoring should flag unusual ScreenConnect communication patterns and outbound connections
- Security teams must verify all software updates through official vendor channels and digital signatures
- Regular audits of installed applications can help identify unauthorized RMM tool deployments
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.