Image: Securonix Threat Research
At a Glance
| Attribute | Detail |
|---|---|
| Actor / group | Unattributed threat actor (tracked by Securonix as SMOKE#SCREEN) |
| Activity type | Multi-wave phishing and RMM abuse for remote access |
| Targets / victims | Windows and macOS users lured by fake software updates |
| Scale | 15 payloads, 5 kill chains, 3 relay servers (per Securonix) |
| Law-enforcement status | No arrests or charges reported |
| Source | Securonix Threat Research |
TL;DR
Securonix is tracking a multi-wave campaign it calls SMOKE#SCREEN. The actor uses fake Zoom, Adobe, and system-update lures to silently install ScreenConnect. This RMM abuse gives attackers legitimate-looking remote control of victim machines.
What Happened
Attackers built a full toolkit around one goal: silent ScreenConnect delivery. Securonix found a live staging server hosting 15 payloads and an open directory listing.
The lures rotate across at least four themes. These include Zoom updates, Adobe updates, business documents, and system-check utilities. As Securonix notes, this variety helps “maximize the population of potential victims.”
How the ScreenConnect RMM Abuse Works
The final payload is always a real, ConnectWise-signed ScreenConnect MSI. That signature is the core of the RMM abuse trick. Many EDR tools trust binaries signed by known vendors.
Securonix calls this “a living-off-the-land technique designed to evade endpoint detections that respect code signing.” Once installed, each agent beacons to an attacker relay using guest-access parameters.
An Evolving Toolkit
The campaign shows a clear arc in tradecraft. Early samples were cautious XOR-encrypted VBScript droppers with sandbox checks. Later loaders grew aggressive.
One batch file runs a nine-step Defender destruction sequence. It disables AMSI, auto-elevates through UAC, kills SmartScreen, and adds Defender exclusions. Securonix confirmed this sequence “completes within 15 seconds of execution.”
Infrastructure and Cross-Platform Reach
The actor spread delivery across trusted services. Phishing pages served payloads through Dropbox, which bypasses many reputation filters. One compiled loader pulled its MSI through a Cloudflare Quick Tunnel.
The threat actor also went cross-platform. A macOS .pkg variant connects to the same primary relay as the Windows installers. Securonix mapped three relay clusters, each with its own RSA key pair, showing deliberate compartmentalization.
Attribution and Confidence
Securonix does not name a known group. Attribution here is low, so the activity stays under the SMOKE#SCREEN tracking label. No arrests or charges have been reported.
Still, one clue stands out. The newest loader source contains the comment “WAIT 3 MINUTES (Breaks Elastic correlation).” This suggests the actor tests directly against commercial security tools.
Impact and Scale
Securonix documented 15 payloads, five kill chains, and three relay servers. The report presents these as observed research figures, not a confirmed victim count. No financial loss figure was published.
The damage can outlast a failed infection. Because the Defender takedown runs first, one loader “leaves the target system permanently degraded even when the subsequent payload download fails.”
How to Stay Protected
Treat unexpected ScreenConnect installs as suspicious. In particular, flag RMM clients that beacon to raw IP addresses. Focus on behavior over signatures. Watch for Defender tampering, AMSI patching, and odd 180-second delays before service starts. Additionally, train users to distrust urgent “update now” pages for Zoom, Adobe, or system tools.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.