TechNewsReel
Live

SMOKE#SCREEN Campaign Uses ScreenConnect RMM to Breach Windows and macOS

Threat actors deploy legitimate remote management tools via fake Adobe and Zoom updates to maintain persistent access.

TechNewsReel Newsroom · August 5, 2026

Securonix Threat Research has uncovered a sophisticated multi-wave malware campaign, codenamed SMOKE#SCREEN, that leverages social engineering to compromise both Windows and macOS systems. By masquerading as trusted software updates and business documents, attackers establish long-term persistence using legitimate enterprise tools.

The campaign employs lures themed as Adobe and Zoom updates, system maintenance utilities, and business document reviews to trick users into executing initial loaders. Once active, the attackers deploy ConnectWise ScreenConnect Remote Monitoring and Management (RMM) agents. To facilitate this, they utilize a WsgiDAV-based staging server at IP 207.174.0.143:8080 to host various payloads, including MSI and EXE files. On macOS, researchers specifically identified a malicious package named 'ZoomUpdateInstaller.pkg'.

Evading Detection

To avoid discovery, SMOKE#SCREEN utilizes a complex toolkit featuring VBScript droppers, .NET executables, and Cloudflare tunnels. The malware includes aggressive anti-analysis checks, refusing to run if the system has less than 2 GB of RAM or if it detects analysis tools such as Wireshark, Process Monitor, VirtualBox, or VMware Tools.

On Windows systems, the loaders are designed to dismantle core security. They attempt to disable Microsoft Defender, modify SmartScreen settings, and create antivirus exclusions—most notably adding the root of the C: drive to the exclusion list to hide their activity. Furthermore, the infrastructure is segmented, with researchers identifying three distinct ScreenConnect relay clusters, each utilizing its own unique RSA key pair.

The RMM Strategy

The use of legitimate RMM software like ScreenConnect represents a growing trend in cyberattacks. By deploying signed, enterprise-grade software, threat actors blend in with standard IT administrative activity. As AppleInsider noted in its summary of the Securonix report, the resulting activity often resembles ordinary technical support, which makes the intrusion significantly harder to identify unless security teams examine exactly how the software arrived and where it is connecting.

Industry Implications

This campaign highlights a high level of adaptability among the operators. According to AppleInsider, a newer loader was discovered that removes aggressive Defender-tampering in favor of a more subtle approach: waiting three minutes between installation and starting the service to break event correlation in Elastic security products.

This ability to pivot techniques in response to commercial security products increases the risk for corporate environments. Because the attack is cross-platform and targets software common in professional settings, it can lead to full system compromise and long-term persistence that evades traditional detection methods.

What to Watch

Organizations should monitor for unauthorized ScreenConnect installations and unusual traffic to Cloudflare tunnels. Security teams are advised to scrutinize any unexpected RMM activity, regardless of whether the software is digitally signed. It remains to be seen if the campaign will expand its lure library beyond the current focus on productivity and communication software.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.