Executive Summary
In August 2026, the Smoke#Screen campaign emerged, leveraging the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool to gain persistent remote access to compromised networks. Attackers employed diverse social engineering lures, including fake Zoom and Adobe updates, business document requests, and system maintenance tools, to trick victims into executing malicious files. This resulted in the silent installation of ScreenConnect agents that connected to attacker-controlled relay servers, providing unauthorized access to both Windows and macOS systems. The campaign's sophistication was evident in its use of rotating payloads and varied lures, making detection challenging.
This incident underscores a growing trend where threat actors exploit legitimate RMM tools to bypass security controls and maintain persistence. The evolving tactics highlight the need for organizations to enhance their defenses against such sophisticated social engineering attacks and to monitor for unauthorized installations of RMM software.
Why This Matters Now
The Smoke#Screen campaign exemplifies the increasing abuse of legitimate RMM tools by cybercriminals to establish covert access to systems. As these tactics evolve, organizations must prioritize behavioral detection mechanisms and employee training to recognize and mitigate such sophisticated social engineering attacks.
Attack Path Analysis
Attackers initiated the campaign by delivering malicious VBScript droppers through social engineering lures, leading to the installation of ScreenConnect for persistent remote access. They then escalated privileges by leveraging the ScreenConnect agent to gain administrative control over the compromised systems. Utilizing this access, they moved laterally across the network to identify and compromise additional systems. The attackers established command and control by configuring ScreenConnect to communicate with attacker-controlled relay servers. They exfiltrated sensitive data by transferring it through the established remote access channels. Finally, they impacted the organization by maintaining persistent access and potentially deploying further malicious activities.
Kill Chain Progression
Initial Compromise
Description
Attackers used social engineering lures, such as fake Zoom and Adobe updates, to trick users into executing VBScript droppers that installed the ScreenConnect RMM tool.
Related CVEs
CVE-2026-3564
CVSS 9An authentication bypass vulnerability in ScreenConnect allows attackers to obtain unauthorized access and escalate privileges by leveraging server-level cryptographic materials.
Affected Products:
ConnectWise ScreenConnect – < 26.1
Exploit Status:
exploited in the wildCVE-2025-14265
CVSS 9.1Improper server-side validation in the ScreenConnect extension framework allows authorized users to install and execute untrusted or arbitrary extensions.
Affected Products:
ConnectWise ScreenConnect – < 25.8
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Remote Access Tools: Remote Desktop Software
System Binary Proxy Execution: Rundll32
Command and Scripting Interpreter: PowerShell
Remote Services: VNC
Screen Capture
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Device Security
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Remote Access Trojan campaigns targeting RMM tools create critical exposure for IT service providers managing client infrastructure through ScreenConnect and similar platforms.
Financial Services
Banking institutions face elevated risk from social engineering attacks leveraging legitimate RMM tools to bypass security controls and maintain persistent network access.
Health Care / Life Sciences
Healthcare organizations vulnerable to HIPAA compliance violations through encrypted traffic exfiltration and lateral movement enabled by compromised remote management tools.
Professional Training
Training organizations susceptible to Zoom update lures and document-review social engineering tactics targeting educational technology platforms and remote learning infrastructure.
Sources
- Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbookhttps://www.darkreading.com/cyberattacks-data-breaches/latest-rmm-fueled-phishing-attack-exposes-threat-actor-playbookVerified
- ScreenConnect vulnerability CVE-2026-3564: Find affected assetshttps://www.runzero.com/blog/screenconnect/Verified
- CVE-2025-14265: Improper server-side validation in ScreenConnect extension frameworkhttps://cve.imfht.com/detail/CVE-2025-14265Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The initial compromise may have been contained to the targeted workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been constrained, limiting their control over additional systems.
Control: East-West Traffic Security
Mitigation: Lateral movement may have been restricted, reducing the number of systems the attacker could compromise.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels could have been detected and disrupted, limiting the attacker's ability to manage compromised systems.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration paths may have been restricted, reducing the volume of data the attacker could transfer out.
The attacker's ability to maintain persistence and execute additional malicious activities could have been limited, reducing the overall impact of the breach.
Impact at a Glance
Affected Business Functions
- IT Support Services
- Remote System Administration
- Network Security Monitoring
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive corporate data due to unauthorized remote access.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of unauthorized access.
- • Deploy Threat Detection & Anomaly Response systems to identify and respond to unauthorized RMM installations and anomalous remote access behaviors.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities and detect suspicious interactions across cloud environments.
- • Apply Inline IPS (Suricata) to inspect and block known exploit patterns and malicious payloads, enhancing network security.



