Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

A new wave of malicious updates has been circulating, posing as legitimate software from Adobe and Zoom. These fake updates are not only installing unwanted software but also granting hackers persistent remote access to compromised computers. The affected parties are widespread, with reports indicating that individuals in various industries have fallen victim to this scheme.

The malicious software at the center of this issue is ScreenConnect, a legitimate remote desktop access tool used by IT professionals and administrators. However, when installed through these fake updates, it allows hackers to gain unauthorized access to infected machines, essentially turning them into “backdoors” for future attacks. This persistent remote access enables attackers to bypass traditional security measures and move laterally within the compromised network.

The process works as follows: a user is tricked into downloading a malicious update from a phishing email or website that appears to be legitimate. Once installed, the fake update installs ScreenConnect, which then establishes a connection with the attacker’s command-and-control server. This allows hackers to remotely access and control infected machines, even if the original malware has been removed.

The reason this issue matters is that it demonstrates the ongoing threat of living off the land (LOTL) attacks. These types of attacks involve using existing tools and software on a compromised machine against its owner or other users within the network. By leveraging ScreenConnect as a Trojan horse, attackers are able to evade traditional security measures and create complex attack paths.

The affected parties include individuals who work in industries such as finance, healthcare, and education, where data protection is of paramount importance. The widespread nature of this issue highlights the need for vigilance among users, particularly when it comes to updates and patches from reputable software vendors.

To protect yourself against these types of attacks, it’s essential to approach all software updates with caution, even if they appear to be legitimate. Always verify the authenticity of an update by checking the vendor’s website or contacting their support team directly. Additionally, keep your operating system and software up-to-date with the latest security patches, as this can help prevent malware from exploiting known vulnerabilities.


Source: The Hacker News — 2026-08-04