Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and M…
Intelligence analysis by Llama

The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server. Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to comprom…
Imagine you get an email that looks like it's from Adobe or Zoom, asking you to update your software. But instead of updating your software, it installs a program that lets the bad guys control your computer from far away. This is called a remote access trojan, and it's a big problem for computer security.
Analysis
A $60B Vote of Confidence
The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Research. The activity has not been attributed to any known threat actor or group. The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan.
Why Cursor?
The initial access vector is assessed to be spear-phishing, with the emails serving as a conduit for an obfuscated Visual Basic Script (aka VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes, and aborts if any of the following executables are running - Wireshark (wireshark.exe) Process Monitor (procmon.exe) Oracle VM VirtualBox (vboxservice.exe) Broadcom VMware Tools (vmtoolsd.exe) Citrix XenServer (xenservice.exe) Fiddler Classic (fiddler.exe)
The Road Ahead
To counter the threat, organizations are recommended to restrict execution of untrusted MSI files, monitor when processes attempt to tamper with security products, audit legitimate use of RMM tools, check for suspicious PowerShell and "cmd.exe" processes, and enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks.
Key points
- The campaign uses social engineering lures to trick victims into installing a remote access trojan.
- The trojan is installed through a series of VBScript droppers, batch file loaders, and compiled .NET executables.
- The trojan provides the attackers with persistent remote access to compromised systems.
- The campaign has not been attributed to any known threat actor or group.
- The findings add to the growing abuse of legitimate RMM tools by threat actors.
If organizations take the recommended steps to secure their systems, they can prevent the installation of remote access trojans and protect their sensitive information.
If organizations fail to take the necessary precautions, they may be vulnerable to attacks that compromise their systems and steal sensitive information.


