Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool

Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool

First seen 4 Aug 2026, 16:28 UTC AppleinsiderFeeds.4SysopsDarkreadingwww.cybersecuritydive.comSecurityaffairs.Co+3 85% similarity 70.2

Article Content

Browse articles
ThreatCluster

The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the campaign utilizes fake Zoom and Adobe updates, as well as business document requests, to lure victims into executing malicious files. Researchers from Securonix reported that the campaign employs a variety of payloads, including VBScript droppers and compiled .NET executables, with a focus on rotating payloads to evade detection. The campaign's infrastructure includes multiple relay servers, allowing attackers to maintain persistent access to compromised networks. While the Windows payloads have been confirmed to infect systems, the macOS package's delivery method remains unclear, and no confirmed infections have been reported on Mac systems. The operation highlights a sophisticated approach to social engineering and malware deployment.

Key Points: • Smoke#Screen campaign uses fake updates to install ScreenConnect for remote access. • Attackers employ diverse social engineering tactics targeting both Windows and macOS. • The campaign features rotating payloads to evade detection and maintain persistence.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
Smoke#Screen campaign reported
Securonix detailed the Smoke#Screen campaign, revealing its use of fake updates to install ScreenConnect on compromised systems.
Darkreading
2026-08-04
MacOS payload identified
The campaign's infrastructure was found to include a macOS package named 'ZoomUpdateInstaller.pkg', but no confirmed infections were reported.
Appleinsider
2026-08-04
Diverse lures documented
Securonix identified multiple social engineering themes used in the campaign, including fake Zoom and Adobe updates.
Feeds.4Sysops

Community

Browse all →