Back Feeds.4Sysops Fake Adobe and Zoom updates turn ScreenConnect into a persistent backdoor
A multi-wave campaign is disguising ConnectWise ScreenConnect as Adobe and Zoom updates, using spear-phishing emails and fake document portals to install persistent remote access on Windows systems. The SMOKE#SCREEN operation uses anti-analysis checks, security-control tampering, and multiple attacker-controlled relay servers to make legitimate RMM software blend into enterprise environments. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
