Skip to content

ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates

Gbhackers Mayura Kathir August 5, 2026

ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents across Windows and macOS endpoints. The result is persistent, “legitimate-looking” remote access that blends into normal IT operations while silently bypassing user awareness and […]

Extracted Entities

Attack Types (1)

Campaigns (1)

MITRE ATT&CK (1)

Platforms (2)

Tools (1)