Cyberattackers are mounting a social engineering campaign to compromise organizations via the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool, in an effort that takes the RMM playbook to new frontiers.
The Smoke#Screen campaign, named by the researchers at Securonix who discovered it, uses lures related to purported Zoom and Adobe "updates," business document requests, and system-maintenance tools. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts, according to a report published today.
While abusing RMM tools has become an increasingly common way for attackers to bypass security controls and maintain persistence on compromised systems, the campaign, which targets both Windows and macOS systems, demonstrates "a clear evolution over time," according to the Securonix researchers. Aaron Beardslee, manager of threat research at Securonix, tells Dark Reading that Smoke#Screen is distinctive for several key reasons.
Related:Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm
Two of those have to do with both rotating payloads and the lures used to hook in victims. "The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and a HTML phishing page, all ultimately pointing to a live … staging server," according to the report, And while it's common practice now for attackers to rotate malware payloads, the attacker's practice of rotating them between individual download sessions is unusual, Beardslee says.
The campaign's lure strategy is similarly distinctive in that attackers used four psychologically different contexts, rather than recycling variations of one social engineering theme, showing sophistication, Beardslee says. Zoom and Adobe updates target consumer habits on unmanaged or bring-your-own-device (BYOD) systems; document-review lures exploit routine enterprise email behavior; and a "SystemCheck" maintenance-tool lure is designed so that a User Account Control (UAC) prompt appears legitimate.
Attackers likely used a wide swath of lures "to maximize the population of potential victims," and also actively rotated payload hashes below download sessions to make "hash-based detection ineffective across multiple investigative sampling periods," according to the report.
Cybercrime OpSec Fail: A Peek Behind the Smoke#Screen Curtain
Securonix's investigation began with a single VBScript dropper (zoom-update.vbs) submitted to its telemetry, which the researchers tracked to an active staging server hosting a full arsenal of 15 unique payloads.
Related:Who's Liable When AI Agents Escape? Hugging Face Breach Raises Hard Questions
... continue reading