[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3Vj8o2MjIBQKXk0C5U88IXgXsyCqi-75SxXsrG_tCeI":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":31},"2dd893d9-ac77-46da-8dbd-73d39f0e73b7","Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook","smoke-screen-rmm-takeover-gambit-exposes-threat-actor-playbook-50d473","The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.","A threat actor, dubbed Smoke#Screen, is actively targeting Remote Monitoring and Management (RMM) tools. The group employs sophisticated social engineering tactics, using diverse lures to trick victims into executing payloads. These payloads deliver ScreenConnect, a legitimate remote access tool, which the attackers then leverage to gain persistent access to compromised networks, likely for further malicious activities.","Threat actor uses social engineering and ScreenConnect for RMM takeover.",null,"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Flatest-rmm-fueled-phishing-attack-exposes-threat-actor-playbook","https:\u002F\u002Feu-images.contentstack.com\u002Fv3\u002Fassets\u002Fblt6d90778a997de1cd\u002Fblt6b501fd239cea948\u002F6a7205c2f2df87f4451c6c0b\u002FPlaybook(1800)_Ivelin_Radkov_Alamy.png?width=720&quality=80&disable=upscale","2026-08-04T18:37:35+00:00","2026-08-04T20:00:05.480331+00:00",7,[18,21,24],{"name":19,"type":20},"Smoke#Screen","threat_actor",{"name":22,"type":23},"ScreenConnect","product",{"name":25,"type":26},"RMM","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":27,"icon":11,"name":29,"slug":30},"Threat Intelligence","threat-intelligence",[32,37,42],{"category":33},{"id":34,"icon":11,"name":35,"slug":36},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":38},{"id":39,"icon":11,"name":40,"slug":41},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":43},{"id":27,"icon":11,"name":29,"slug":30},[45],{"type":36,"value":22,"context":46},"Delivered payload for persistent remote access"]