Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for
- Securonix uncovers SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs
- Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery
- Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs
Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management (RMM) software.
Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to convince the victims to run malicious files.
Victims who don’t see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE