Particle.news
Download on the App Store

SMOKE#SCREEN Campaign Uses Fake Updates to Install ScreenConnect and Give Attackers Remote Access

Securonix researchers warn the operation uses legitimate signed RMM installers and trusted hosting to route infected agents to attacker-controlled relay servers and evade detection.

Overview

  • Researchers traced the campaign to a live WsgiDAV staging server and published findings on Tuesday that show social-engineered lures install ScreenConnect clients configured to contact three separate attacker-controlled relay clusters.
  • Attackers deliver payloads with polished fake Zoom or Adobe update pages, business-document and maintenance-themed files, Dropbox links and Cloudflare Quick Tunnel endpoints to trick users into running installers.
  • The final payloads are genuine ConnectWise ScreenConnect installers signed with a DigiCert chain that are reconfigured to beacon to attacker relays, giving operators persistent remote desktop and management access that looks like normal IT activity.
  • Early Windows loaders tried to weaken Microsoft Defender and SmartScreen and add Defender exclusions but later samples removed that behavior and introduced multi-minute delays and encrypted bundles to avoid endpoint-detection correlation.
  • Securonix urges defenders to inventory approved RMM tools, block or flag ScreenConnect agents that connect to raw IPs, restrict untrusted MSI execution, monitor for security-process tampering and inspect how any ScreenConnect install was launched.