Fake Zoom update malware campaign expands its reach to macOS
A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac. Fake Zoom update Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS…
A malware campaign known as Smoke#Screen is spreading its reach to macOS, expanding beyond its previous targeting of Windows systems. Researchers from Securonix, a cybersecurity firm, detailed the campaign in an August 4 report. The attack involves fake Zoom updates and business files, designed to install ScreenConnect, a legitimate remote monitoring and management software used by IT departments.
However, in this case, the scripts, loaders, phishing page, and macOS package named "ZoomUpdateInstaller.pkg" are all traced back to shared infrastructure. Once downloaded, the genuine ScreenConnect client is configured to connect to attacker-controlled relay servers instead of the intended company system. This allows attackers to gain remote desktop and management capabilities, activities that may appear legitimate and harder to detect without further investigation into how the software was received and its connection points.
Written by urgent.news from AppleInsider's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.