TechNewsReel
Live

Smoke#Screen Campaign Uses Legitimate RMM Tools to Bypass Security

Threat actors are using rotating lures and trusted software signatures to deploy ScreenConnect agents for persistent remote access.

TechNewsReel Newsroom · August 4, 2026

Threat actors are conducting a sophisticated social engineering campaign, codenamed "Smoke#Screen," to deploy ScreenConnect Remote Monitoring and Management (RMM) agents on Windows and macOS systems. By tricking users into installing legitimate administrative tools, the attackers gain persistent, high-level remote access to compromised machines.

According to researchers at Securonix, the campaign utilizes four distinct psychological lures to deceive targets. These include fake Zoom and Adobe updates designed to exploit consumer habits, business document reviews targeting enterprise employees, and a "SystemCheck" maintenance tool intended to make User Account Control (UAC) prompts appear legitimate. The attack toolkit is diverse, employing VBScript droppers, batch file loaders, compiled .NET executables, and HTML phishing pages to deliver the payload. To evade detection, the actors leveraged Dropbox for reputation, Cloudflare Quick Tunnels for anonymity, and legitimate ConnectWise DigiCert signatures on their payloads. Securonix identified three separate ScreenConnect relay servers and reconstructed five distinct kill chains during their investigation.

The Rise of RMM Abuse

The abuse of legitimate RMM tools has become a primary strategy for threat actors seeking to maintain persistence while bypassing Endpoint Detection and Response (EDR) systems. Because these tools are signed by trusted vendors and perform functions common to corporate IT environments—such as remote desktop control—they rarely trigger traditional malware alerts. In this instance, the attackers' operational security lapsed when they accidentally left their C# source code on an open directory next to compiled builds, allowing researchers to analyze their development process directly.

Implications for Security

Smoke#Screen represents an evolution in RMM abuse through the use of "rotating payloads" between individual download sessions, a tactic that renders traditional hash-based detection ineffective. By combining trusted software signatures with anonymity tools, the actors create a significant blind spot for security teams who rely on reputation-based filters rather than behavioral analysis.

"The payload isn't malware, and that's the whole problem," said Aaron Beardslee, manager of threat research at Securonix. "There's no C2 protocol to signature, no unsigned binary, no injected process, nothing weird in the process tree after install, just a properly signed ConnectWise service doing exactly what ConnectWise built it to do."

Future Outlook

Security professionals are advised to monitor for unauthorized RMM installations and shift toward behavioral monitoring to detect anomalous remote access patterns. While the exposure of the attackers' source code provides a rare glimpse into their playbook, the campaign's ability to blend in with legitimate IT traffic suggests that similar "living-off-the-land" tactics will remain a persistent threat to enterprise environments.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.