Interestana
Home/News/Fake Adobe, Zoom Updates Deploy ScreenConnect
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Fake Adobe, Zoom Updates Deploy ScreenConnect

Fake Adobe, Zoom Updates Deploy ScreenConnect

Cybersecurity researchers have detailed an active, multi-wave campaign that leverages social engineering tactics to deploy Remote Monitoring and Management (RMM) programs, specifically ConnectWise ScreenConnect. This campaign, codenamed SMOKE#SCREEN by Securonix Threat Labs, utilizes deceptive lures centered on common software updates for Adobe and Zoom, as well as themes of business document review and system maintenance utilities. The primary objective of these attacks is to gain persistent remote access to victim systems, enabling further malicious activities.

The campaign's methodology involves distributing malicious executables disguised as legitimate software update installers. When users are tricked into executing these files, the malware silently installs ConnectWise ScreenConnect, a legitimate RMM tool that is often abused by threat actors. This RMM software allows for unattended remote access and control of infected machines, making it a valuable asset for attackers seeking to maintain a foothold within a compromised network. The use of ScreenConnect is particularly concerning due to its legitimate business applications, which can help attackers blend in with normal network traffic and operations.

Securonix Threat Labs observed that the campaign has evolved through multiple waves, indicating a persistent and adaptive threat actor. Initial waves focused on delivering payloads via email attachments, while later stages expanded to include malicious links and potentially compromised websites. The social engineering aspect is crucial to the campaign's success, relying on users' trust in familiar software vendors like Adobe and Zoom, and their perceived need to keep software up-to-date or review important business documents. The threat actors exploit this by creating convincing fake update notifications or document review prompts that lead users to download and run the malicious installers.

The implications of this campaign are significant for businesses and individuals alike. The deployment of ScreenConnect can lead to data theft, ransomware deployment, or the use of compromised systems as part of a larger botnet. The persistent nature of the RMM tool means that even if initial detection measures are bypassed, the attackers can regain access to the system later. Organizations are advised to enhance their endpoint detection and response (EDR) capabilities, educate employees about phishing and social engineering risks, and ensure that all software is updated through official channels only. Verifying the authenticity of update prompts and scrutinizing email attachments and links are critical preventative measures against this evolving threat.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next