Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Summary
An ongoing, multi-wave campaign is using social engineering tactics disguised as Adobe and Zoom software updates to trick users into installing Remote Monitoring and Management (RMM) tools, such as ConnectWise ScreenConnect. This campaign, tracked as SMOKE#SCREEN, aims to gain persistent remote access to victim systems.
IFF Assessment
The campaign's use of social engineering to deploy RMM tools for persistent access represents a significant threat to organizations and defenders.
Defender Context
Defenders should be aware of these social engineering tactics that leverage common software update lures to deploy RMM tools. User education on verifying update sources and scrutinizing unexpected prompts is crucial to mitigate this threat. Organizations should also monitor for unauthorized RMM tool installations and ensure endpoint detection and response (EDR) solutions are configured to detect and block such deployments.