Cybersecurity researchers report an active, multi-stage social-engineering campaign that uses fake software update themes—specifically Zoom and Adobe—alongside business-document and system-maintenance lures to deliver Remote Monitoring and Management (RMM) capabilities. The campaign, tracked as SMOKE#SCREEN by Securonix Threat Intelligence, targets victims with phishing and staged payloads that include Windows scripts and compiled components, as well as an HTML phishing page. Researchers also describe infrastructure and artifacts reused across platforms, including a macOS package labeled “ZoomUpdateInstaller.pkg,” indicating the activity extends to macOS as well as Windows.
Once delivered, the malware installs or leverages ConnectWise ScreenConnect, a legitimate RMM product used by many IT teams. The installers configure genuine ScreenConnect components so they call attacker-controlled relay servers rather than an authorized company endpoint. After connection, the software can provide remote desktop and management functions to the attacker, making the behavior potentially resemble routine IT support or remote administration. This persistence through legitimate tooling can complicate detection, since the remote-access software itself appears legitimate while its configuration and connections are malicious.