Executive Summary
In August 2026, cybersecurity researchers identified an active campaign, dubbed SMOKE#SCREEN, leveraging social engineering tactics themed around Adobe and Zoom software updates to deploy Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect. The attackers utilized VBScript droppers, batch file loaders, and .NET executables, directing victims to a WsgiDAV-based staging server. Successful breaches resulted in persistent remote access to compromised systems via ScreenConnect agents connecting to attacker-controlled relay servers. The campaign's initial access vector was spear-phishing emails containing obfuscated VBScript droppers that performed environment checks before executing malicious payloads. Notably, the attackers employed trusted hosting services like Dropbox and Cloudflare to evade detection, highlighting the increasing abuse of legitimate RMM tools to bypass security controls and blend into enterprise environments.
This incident underscores a growing trend where threat actors exploit legitimate RMM tools to establish persistent access within enterprise networks. The use of trusted platforms for payload delivery complicates detection and mitigation efforts, emphasizing the need for organizations to enhance monitoring of RMM tool usage and implement stringent controls over software update processes to prevent similar attacks.
Why This Matters Now
The SMOKE#SCREEN campaign highlights the urgent need for organizations to scrutinize the use of legitimate RMM tools within their networks, as threat actors increasingly exploit these tools to gain persistent access. The abuse of trusted platforms for payload delivery complicates detection, necessitating enhanced monitoring and stringent controls over software update processes to prevent similar attacks.
Attack Path Analysis
The SMOKE#SCREEN campaign began with spear-phishing emails containing malicious VBScript droppers disguised as software updates, leading to the installation of the ScreenConnect RMM tool. The VBScript droppers performed environment checks and disabled security features to escalate privileges, facilitating the execution of malicious payloads. Once installed, ScreenConnect provided attackers with persistent remote access, enabling lateral movement within the network. The RMM tool established command and control channels through attacker-controlled relay servers, allowing continuous communication. Attackers could exfiltrate sensitive data via the established remote access channels. The campaign's impact included unauthorized access, potential data theft, and disruption of business operations.
Kill Chain Progression
Initial Compromise
Description
Spear-phishing emails with malicious VBScript droppers disguised as software updates led to the installation of ScreenConnect RMM tool.
Related CVEs
CVE-2024-1709
CVSS 10An authentication bypass vulnerability in ConnectWise ScreenConnect allows unauthenticated remote attackers to gain access to sensitive information and critical systems.
Affected Products:
ConnectWise ScreenConnect – <= 23.9.7
Exploit Status:
exploited in the wildCVE-2024-1708
CVSS 8.4A path traversal vulnerability in ConnectWise ScreenConnect allows remote attackers to perform remote code execution and access sensitive data.
Affected Products:
ConnectWise ScreenConnect – <= 23.9.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Attachment
Visual Basic
MSIExec
File Deletion
Registry Run Keys / Startup Folder
Obfuscated Files or Information
Disable or Modify Tools
Remote Access Software
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – User Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Remote Access Trojans exploiting software updates pose critical threats to IT infrastructure, bypassing security controls through legitimate RMM tools and encrypted traffic vulnerabilities.
Financial Services
ScreenConnect deployment via social engineering threatens financial networks, enabling lateral movement and data exfiltration while violating PCI DSS and encryption compliance requirements.
Computer Software/Engineering
Fake Adobe/Zoom updates target software development environments, compromising source code repositories, development tools, and enabling persistent remote access through legitimate channels.
Health Care / Life Sciences
Healthcare systems face HIPAA violations through encrypted traffic exploitation and segmentation bypasses, allowing unauthorized access to patient data and medical device networks.
Sources
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Accesshttps://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.htmlVerified
- High-Risk Vulnerabilities in ConnectWise ScreenConnecthttps://www.rapid7.com/blog/post/2024/02/20/etr-high-risk-vulnerabilities-in-connectwise-screenconnect/Verified
- Active Exploitation of Multiple Vulnerabilities in ConnectWise ScreenConnect Softwarehttps://www.csa.gov.sg/alerts-and-advisories/alerts/al-2024-022/Verified
- Critical Authentication Bypass Vulnerability in ScreenConnect (CVE-2024-1709)https://www.upguard.com/blog/screenconnect-cve-2024Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the SMOKE#SCREEN campaign as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise may still occur, CNSF would likely limit the attacker's ability to exploit the compromised system to reach other workloads.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely limit the attacker's ability to leverage escalated privileges to access other segments of the network.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit the attacker's ability to move laterally by enforcing strict controls on internal traffic.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely limit the attacker's ability to establish and maintain command and control channels across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit the attacker's ability to exfiltrate data by enforcing strict outbound traffic policies.
With CNSF controls in place, the impact of unauthorized access and data theft would likely be limited to the initially compromised workload, reducing overall business disruption.
Impact at a Glance
Affected Business Functions
- IT Operations
- Remote Support Services
- System Administration
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive business documents and system credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of threats within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network traffic and detect anomalous activities across cloud environments.
- • Deploy Threat Detection & Anomaly Response mechanisms to identify and respond to suspicious behaviors indicative of RMM tool abuse.
- • Establish Inline IPS (Suricata) to detect and prevent known exploit patterns and malicious payloads, enhancing overall network security.



