Fake Adobe & Zoom Updates Deploy ScreenConnect for Persistent Access
The SMOKE#SCREEN campaign exploits users' trust in familiar software brands like Adobe and Zoom to trick them into executing malicious update packages that install legitimate remote management tools for persistent backdoor access. By abusing trusted RMM software such as ConnectWise ScreenConnect, attackers blend malicious activity into normal-looking traffic, making detection significantly harder. The use of trusted delivery platforms like Dropbox and Cloudflare Quick Tunnel further obscures the attack chain from traditional security controls. This matters because once ScreenConnect is installed, attackers gain durable, low-noise remote access that can persist through reboots and evade endpoint defenses for extended periods.
Tactical Insight
Immediate actions
- Block or alert on unauthorized installation of RMM tools (e.g., ScreenConnect, AnyDesk) not approved by your organization's software allowlist.
- Restrict user permissions so standard accounts cannot install software or execute VBScript and batch file payloads without administrative approval.
- Block known malicious staging infrastructure (207.174.0[.]143:8080) and audit DNS/proxy logs for connections to Cloudflare Quick Tunnel domains used as C2.
Detection measures
- Deploy behavioral detection rules to flag VBScript droppers, suspicious .NET executable launches, and RMM tool installations originating from user-space directories.
- Monitor for outbound connections from RMM tools to unexpected external endpoints and alert on first-time-seen C2 cluster patterns.
- Correlate endpoint telemetry with network logs to identify multi-stage dropper chains characteristic of this campaign.
Long-term improvements
- Conduct regular security awareness training focused on social engineering tactics, specifically fake software update lures impersonating trusted vendors.
- Implement application allowlisting to prevent unapproved executables, scripts, and RMM clients from running on endpoints.
- Establish a formal software inventory and change management process so any new RMM tool installation triggers an automatic review workflow.