discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and M…

By Ravie Lakshmanan·Aug 4·thehackernews.com·2 min read

Intelligence analysis by Llama

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Image: thehackernews.com

The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server. Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to comprom…

Why it matters

The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan.

Imagine you get an email that looks like it's from Adobe or Zoom, asking you to update your software. But instead of updating your software, it installs a program that lets the bad guys control your computer from far away. This is called a remote access trojan, and it's a big problem for computer security.

Analysis

A $60B Vote of Confidence

The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Research. The activity has not been attributed to any known threat actor or group. The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan.

Why Cursor?

The initial access vector is assessed to be spear-phishing, with the emails serving as a conduit for an obfuscated Visual Basic Script (aka VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes, and aborts if any of the following executables are running - Wireshark (wireshark.exe) Process Monitor (procmon.exe) Oracle VM VirtualBox (vboxservice.exe) Broadcom VMware Tools (vmtoolsd.exe) Citrix XenServer (xenservice.exe) Fiddler Classic (fiddler.exe)

The Road Ahead

To counter the threat, organizations are recommended to restrict execution of untrusted MSI files, monitor when processes attempt to tamper with security products, audit legitimate use of RMM tools, check for suspicious PowerShell and "cmd.exe" processes, and enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks.

Key points

  • The campaign uses social engineering lures to trick victims into installing a remote access trojan.
  • The trojan is installed through a series of VBScript droppers, batch file loaders, and compiled .NET executables.
  • The trojan provides the attackers with persistent remote access to compromised systems.
  • The campaign has not been attributed to any known threat actor or group.
  • The findings add to the growing abuse of legitimate RMM tools by threat actors.
The Upside

If organizations take the recommended steps to secure their systems, they can prevent the installation of remote access trojans and protect their sensitive information.

The Downside

If organizations fail to take the necessary precautions, they may be vulnerable to attacks that compromise their systems and steal sensitive information.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycybersecurityremote-access-trojanrmm-toolsscreenconnect

Author

Ravie Lakshmanan

Intelligence analysis by

Llama

Published

Aug 4, 2026

Source

thehackernews.com

Share

Topics

securitycybersecurityremote-access-trojanrmm-toolsscreenconnect

Related

More from this desk

Aug 4·bleepingcomputer.com

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware targets thousands of macOS users through compromised Xcode projects and GitHub repositories. The malware features enhanced evasion techniques and introduces two new components.

Aug 4·schneier.com

Iran Cyberattacks Against Minnesota Water Systems

Iran is suspected of conducting cyberattacks against water systems in Minnesota, with at least seven states targeted. The US government has not confirmed the source of the attacks, with President Trump attributing them to Minnesota's incompetence.

Aug 4·bleepingcomputer.com

77 Open VSX extensions found harvesting developer info

77 Open VSX extensions were found to be harvesting developer information, including system details and development environment metadata. The extensions, which were discovered by Manifold Security, did not access source code or credentials but did collect information that …

Aug 4·thehackernews.com

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

Greatness PhaaS, a commercial phishing-as-a-service toolkit, has added support for device code phishing, a rapidly growing cyber threat that bypasses Multi-Factor Authentication (MFA) and steals user tokens.