Fake Zoom and Adobe Updates Deliver Remote Access Malware on macOS and Windows

Fake Zoom and Adobe Updates Deliver Remote Access Malware on macOS and Windows

First seen 4 Aug 2026, 16:28 UTC AppleinsiderFeeds.4Sysopswww.securonix.com 86% similarity 51.9

Article Content

Browse articles
ThreatCluster

A malware campaign named Smoke#Screen is using fake Zoom and Adobe updates to install ScreenConnect, a legitimate remote management tool, as a backdoor on both Windows and macOS systems. Researchers from Securonix reported that the campaign employs social engineering tactics, including spear-phishing emails and fake document portals, to trick users into executing malicious files. The campaign has been observed to utilize multiple relay servers and anti-analysis techniques to blend into enterprise environments. Although the macOS payload has been identified, there are no confirmed infections reported on Mac systems yet. The primary focus of the campaign appears to be Windows systems, with several payloads already confirmed to have been delivered. The operation is designed to make unauthorized access appear legitimate, complicating detection efforts. Securonix's report highlights the ongoing trend of using familiar software brands to lure users into executing malware.

Key Points: • Smoke#Screen campaign uses fake updates to install ScreenConnect on Windows and macOS. • Attackers employ social engineering tactics, including phishing emails and fake portals. • No confirmed Mac infections reported, but the macOS payload has been identified.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Smoke#Screen campaign reported
Securonix detailed the malware campaign using fake Zoom and Adobe updates to install ScreenConnect.
Appleinsider
2026-08-04
Fake updates identified
The campaign disguises ScreenConnect as legitimate updates to gain unauthorized access to systems.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story