Skip to content
Fake Adobe and Zoom updates turn ScreenConnect into a persistent backdoor

Fake Adobe and Zoom updates turn ScreenConnect into a persistent backdoor

Feeds.4Sysops IT News August 4, 2026

A multi-wave campaign is disguising ConnectWise ScreenConnect as Adobe and Zoom updates, using spear-phishing emails and fake document portals to install persistent remote access on Windows systems. The SMOKE#SCREEN operation uses anti-analysis checks, security-control tampering, and multiple attacker-controlled relay servers to make legitimate RMM software blend into enterprise environments. Source

Extracted Entities

Attack Types (1)

Campaigns (1)

MITRE ATT&CK (1)

Platforms (1)