Particle.news
Download on the App Store

SMOKE#SCREEN Campaign Uses Legitimate ScreenConnect Installs to Give Attackers Persistent Access

Securonix researchers say operators reconfigure vendor-signed ScreenConnect clients to call attacker-run relay servers so intrusions look like normal IT activity.

Overview

  • Securonix disclosed the campaign on August 4–5 after tracing a VBScript dropper to a publicly browsable WsgiDAV server at 207.174.0.143 that hosted multiple payloads and ScreenConnect relays.
  • Attackers use social-engineering lures that mimic Zoom and Adobe updates and business documents to get victims to run installers that ultimately deploy ConnectWise ScreenConnect.
  • Final payloads are genuine ConnectWise MSIs signed with a valid DigiCert Authenticode chain and are repointed to three attacker-controlled relay clusters to provide persistent remote desktop access.
  • The toolset includes VBScript droppers, batch and compiled .NET loaders, Dropbox and Cloudflare delivery, and a macOS package tied to the same relay while Windows infections have been observed.
  • Defenders are urged to favor behavioral checks over signature scans by auditing approved RMM use, alerting on Defender/AMSI tampering, blocking ScreenConnect connections to raw IPs, and restricting MSI execution from TEMP or AppData.