


Perceptive Security
SOC/SIEM Consultancy

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Published:
4 August 2026 at 13:11:22
Alert date:
4 August 2026 at 15:02:03
Source:
thehackernews.com
Ransomware & Malware, Identity & Access, Data Breach & Exfiltration, Email & Messaging
A multi-wave social engineering campaign dubbed SMOKE#SCREEN by Securonix researchers has been actively deploying Remote Monitoring and Management (RMM) tools, specifically ConnectWise ScreenConnect. The campaign uses lures themed around fake Adobe and Zoom software updates, business document reviews, and system maintenance utilities. Once installed, ScreenConnect provides attackers with persistent remote access to compromised systems. The campaign is notable for its use of legitimate RMM software to blend in with normal enterprise activity. Multiple wave delivery suggests ongoing refinement of attack methods. The use of trusted software brand names (Adobe, Zoom) increases the likelihood of successful social engineering. This type of attack is particularly dangerous in enterprise environments where RMM tools are commonly used.
Technical details
Two distinct campaigns were identified. Campaign 1 (SMOKE#SCREEN): An active multi-wave campaign using social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to deploy ConnectWise ScreenConnect RMM tool. The toolkit includes VBScript droppers, batch file loaders, compiled .NET executables, and an HTML phishing page, all pointing to a WsgiDAV-based staging server at 207.174.0[.]143:8080. Initial access is via spear-phishing emails delivering obfuscated VBScript droppers that perform environment and anti-analysis checks (checking for Wireshark, Process Monitor, VirtualBox, VMware Tools, XenServer, Fiddler). If checks pass, a PowerShell command fetches a C# payload from 207.189.11[.]170. A third delivery variant uses a compressed archive containing a batch script that disables AMSI, escalates privileges via UAC prompt, disables SmartScreen via Registry modifications, removes Zone.Identifier ADS from the MSI file, and installs ScreenConnect. Payloads were hosted on Dropbox and delivered via Cloudflare Quick Tunnels (subscription-magnetic-recommended-meat.trycloudflare.com). Three distinct C2 clusters were identified based on ScreenConnect relay configuration strings. ScreenConnect beacons to attacker-controlled relay servers on port 8041. Campaign 2 (Powercat/Fake Xeno Roblox): Fake Xeno Executor installers distributed via gaming forums and Discord initiate a multi-stage Java infection chain. A 'xeno.exe' runs the first stage, checks for Java Runtime Environment, reads 'XenoIcon.jpg' for C2 validation keys, contacts C2 at solthere[.]net, then launches an obfuscated JAR file disguised as 'decompiler.exe'. The final payload (Powercat) is a Java-based stealer and surveillance malware capable of credential theft, browser cookie theft, Discord/Roblox/Minecraft account theft, cryptocurrency wallet theft, keylogging, webcam access, desktop streaming, file manipulation, PowerShell command execution, and interactive shell access. It targets Exodus wallet version 26.1.5 specifically by unpacking app.asar and injecting JavaScript to capture tokens.
Mitigation steps:
1. Restrict execution of untrusted MSI files across the environment. 2. Monitor for processes attempting to tamper with security products (AMSI, SmartScreen, Defender). 3. Audit legitimate use of RMM tools such as ScreenConnect and flag unauthorized installations. 4. Monitor for suspicious PowerShell and cmd.exe process activity. 5. Enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks. 6. Block or monitor connections to identified IOC IPs and domains: 207.174.0[.]143, 207.189.11[.]170, solthere[.]net. 7. Monitor for VBScript and batch script execution from email-delivered files. 8. Block or alert on Zone.Identifier ADS removal from downloaded files. 9. Monitor for ScreenConnect relay connections, especially on port 8041. 10. Educate users to not run software updates delivered via email or unofficial channels. 11. Monitor Dropbox and Cloudflare tunnel traffic for payload delivery. 12. Implement application allow-listing to prevent unauthorized RMM tool installation. 13. Block execution of Java-based payloads from untrusted sources. 14. Monitor gaming forums and Discord communities for malware distribution campaigns targeting employees.
Affected products:
ConnectWise ScreenConnect (RMM tool - abused)
Adobe (impersonated in lures)
Zoom (impersonated in lures)
Windows (AMSI
SmartScreen
UAC targeted)
Exodus Wallet version 26.1.5
Brave Browser
Google Chrome
Microsoft Edge
Opera
Opera GX
Vivaldi
Atomic Wallet
Cake Wallet
Monero Wallet
SafePal
Tron Wallet
Git
JetBrains tools
Microsoft Visual Studio
Python IDLE
Battle.net
Epic Games Launcher
Riot Client
Rockstar Games Launcher
Steam
ExpressVPN
Mullvad VPN
NordVPN
Surfshark
Discord
Snapchat
Telegram
WhatsApp
Roblox
Minecraft (Feather
Lunar
Meteor
Modrinth
Prism
official launcher)
Related links:
https://www.securonix.com/blog/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels/
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
https://www.threatlocker.com/blog/powercat-malware-campaign-fake-game-cheats-deliver-infostealer-targeting-discord-roblox-and-crypto-wallets
https://thehackernews.com/2025/09/malicious-npm-package-nodejs-smtp.html
Related CVE's:
Related threat actors:
IOC's:
207.174.0[.]143:8080 (WsgiDAV staging server / C2), 207.189.11[.]170 (C# payload host), subscription-magnetic-recommended-meat.trycloudflare.com (Cloudflare Quick Tunnel), solthere[.]net (Powercat C2 server), zoom-update.html (phishing page), MemoryLoader.cs (compiled .NET loader), XenoIcon.jpg (file containing C2 validation keys), decompiler.exe (obfuscated JAR file), xeno.exe (fake Xeno Executor malware dropper), cloudflared.exe (used by threat actor on infrastructure), Port 8041 (ScreenConnect relay communication port)
This article was created with the assistance of AI technology by Perceptive.
