Skip to content
Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool

Smoke#Screen Campaign Uses Fake Updates to Install Remote Access Tool

First seen 4 Aug 2026, 16:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 16:12 UTC
  • Smoke#Screen campaign uses fake updates to install ScreenConnect for remote access.
  • Attackers employ diverse social engineering tactics targeting both Windows and macOS.
  • The campaign features rotating payloads to evade detection and maintain persistence.

The Smoke#Screen campaign exploits social engineering tactics to install the legitimate ScreenConnect RMM tool on compromised systems, providing attackers with remote access. Targeting both Windows and macOS, the campaign utilizes fake Zoom and Adobe updates, as well as business document requests, to lure victims into executing malicious files. Researchers from Securonix reported that the campaign employs a variety of payloads, including VBScript droppers and compiled .NET executables, with a focus on rotating payloads to evade detection. The campaign's infrastructure includes multiple relay servers, allowing attackers to maintain persistent access to compromised networks. While the Windows payloads have been confirmed to infect systems, the macOS package's delivery method remains unclear, and no confirmed infections have been reported on Mac systems. The operation highlights a sophisticated approach to social engineering and malware deployment.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-08-04
Smoke#Screen campaign reported
Securonix detailed the Smoke#Screen campaign, revealing its use of fake updates to install ScreenConnect on compromised systems.
Darkreading
2026-08-04
MacOS payload identified
The campaign's infrastructure was found to include a macOS package named 'ZoomUpdateInstaller.pkg', but no confirmed infections were reported.
Appleinsider
2026-08-04
Diverse lures documented
Securonix identified multiple social engineering themes used in the campaign, including fake Zoom and Adobe updates.
Feeds.4Sysops

More articles in this cluster (8)

Following this threat?

Track Chaos Ransomware, MuddyWater and Adobe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed