Security firm Securonix has detailed an active multi-wave campaign codenamed SMOKE#SCREEN that uses social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily install Remote Monitoring and Management software on Windows systems. The goal, according to the researchers, is persistent operator-level remote access through ConnectWise ScreenConnect rather than a one-time payload delivery.
How SMOKE#SCREEN’s Fake Update Lures Deliver ScreenConnect
The campaign relies on rotating payloads and a diverse set of lures that change between waves, which makes the phishing attempts harder to block on static indicators. Targets are drawn into the lures through everyday themes — a pending software update, a document that needs review, or a system maintenance task — that a user would not think twice about acting on.
The Adobe, Zoom, and Business-Document Lure Themes
Securonix detailed lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities. The Adobe and Zoom angles are particularly effective because both companies push frequent, legitimate update notifications, so users have been conditioned to accept update prompts without scrutiny. The business-document and maintenance themes extend the campaign beyond software updates into the kinds of workflow prompts employees see daily.
Rotating Payloads and Multi-Wave Distribution
Securonix observed the campaign running in waves with different lure themes and payload variants carrying the same end objective. Because the delivery mechanism shifts between waves, defenders cannot simply block a single file hash or domain; the campaign’s operational pattern is the more stable signal, and monitoring for the arrival of unexpected RMM tools is more reliable than tracking any individual lure.
Why ScreenConnect Installation Is the Key Warning Sign
The abuse of Remote Monitoring and Management software is a well-documented precursor to ransomware and data theft, and ScreenConnect specifically gives an attacker a persistent, operator-level remote access channel that can operate with a level of visibility and control that typical malware lacks. The tool runs with legitimate privileges on the compromised machine, which can allow it to bypass endpoint detection that would otherwise flag unknown executables.
The Persistent Remote-Access Risk From an RMM Implant
Because ScreenConnect is a legitimate product, its presence on a system is not inherently suspicious to many security tools, and attackers can use the management interface to move laterally, deploy additional tools, or maintain access even after the original phishing vector is removed. That persistence is the core threat SMOKE#SCREEN is designed to achieve, and the operator-level access it grants is the same level of control a legitimate IT administrator would have.
Detecting and Responding to Unexpected ScreenConnect Installations
Securonix published detection guidance focused on monitoring for unexpected ScreenConnect installations and unusual RMM usage, restricting which remote management tools are permitted in the environment, and blocking fake-update lures before they reach users. The firm’s advice treats the appearance of an unexplained RMM tool as a compromise signal rather than a benign software install.
The Policy Question Around Approved Remote Management Tools
For organizations that rely on legitimate RMM tools, the guidance points to a policy question: if remote management software is not expected on a given machine, its appearance should trigger an investigation, and organizations should maintain an inventory of which hosts are authorized to run which tools. That inventory is what makes an unexpected ScreenConnect install visible; without it, the tool blends into the environment as unremarkable software. The campaign’s use of common software-update themes also highlights the difficulty of user awareness training, since the lures mimic the routine prompts employees already encounter.
The pattern behind SMOKE#SCREEN — phishing into RMM abuse — mirrors earlier campaigns that used remote management tools as a persistence vehicle, and the tactic shows no sign of declining because it remains effective. The practical consequence for defenders is that RMM software must be treated as an administrative-tier capability: locked down, inventoried, and monitored, because in the hands of an attacker it becomes a durable backdoor rather than a support utility.
The campaign also illustrates how attackers have repurposed a class of software built for legitimate remote support. ConnectWise ScreenConnect and similar tools were designed to give administrators control over endpoints; when an attacker installs the same tool through a phishing lure, they inherit that administrative control without needing to develop custom remote-access malware. For security teams, that means the distinction between authorized and unauthorized RMM use is the critical control, and that distinction only exists if the organization knows which tools are supposed to be running where.
