Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for
SMOKE#SCREEN is a dangerous campaign that evolves over time to avoid being spotted by defenders.
Securonix has discovered a fresh malicious campaign known as SMOKE#SCREEN, which employs fake Zoom, Adobe update notifications, and a range of fraudulent business documents to trick users into installing a legitimate remote monitoring and management (RMM) software, ConnectWise ScreenConnect. Once activated, the attackers can remotely access the compromised devices, which can lead to data theft, installation of additional malware, or infiltration of the organization's network.
Initially, SMOKE#SCREEN appeared to be an ordinary phishing campaign where victims were tricked into installing legitimate RMM and granting remote access. However, what sets it apart is its evolution, as newer versions of the campaign attempt to disable security measures and evade detection by security software. The attackers used trusted services, such as Dropbox and Cloudflare, to deliver their files, making it harder for security products to block them.
SMOKE#SCREEN has affected both Windows and macOS users. The researchers from Securonix noted that the campaign represents a proficient, continually maintained, and agile threat actor who has developed a diverse toolkit aimed at gaining persistent, seemingly legitimate remote access to victim systems through weaponized ScreenConnect deployments.
This indicates that the threat actor is well-equipped and adheres to operational security practices. To reduce the risk of compromise, businesses should disable automatic software updates received via email, verify update requests through official websites, and educate their employees to exercise caution when opening unexpected attachments or installing tools.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.