🟠 High | Source: The Hacker News
Attackers are running a multi-wave social engineering campaign, dubbed SMOKE#SCREEN, that tricks users into installing ConnectWise ScreenConnect by disguising it as legitimate Adobe or Zoom software updates, document reviews, or system maintenance tools. Once installed, ScreenConnect gives attackers persistent, legitimate-looking remote access to compromised machines. Because RMM tools are trusted by most security controls, this activity is difficult to detect and evict.
Security Architect’s Take: Audit your environment for unauthorised or unexpected ScreenConnect/ConnectWise installations and enforce application allowlisting to block unapproved RMM tools. Ensure endpoint policies restrict the execution of software installers downloaded from the web by standard users, and consider blocking ScreenConnect’s known C2 domains at your proxy or firewall if the tool is not sanctioned in your organisation.
Original advisory: Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access