Feeds.4Sysops
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the campaign utilizes fake Zoom and Adobe updates, as well as business document requests, to lure victims into executing malicious files. Researchers from Securonix reported that the campaign employs a variety of payloads, including VBScript droppers and compiled .NET executables, with a focus on rotating payloads to evade detection. The campaign's infrastructure includes multiple relay servers, allowing attackers to maintain persistent access to compromised networks. While the Windows payloads have been confirmed to infect systems, the macOS package's delivery method remains unclear, and no confirmed infections have been reported on Mac systems. The operation highlights a sophisticated approach to social engineering and malware deployment.
Key Points: • Smoke#Screen campaign uses fake updates to install ScreenConnect for remote access. • Attackers employ diverse social engineering tactics targeting both Windows and macOS. • The campaign features rotating payloads to evade detection and maintain persistence.