Cyberattackers have launched a sophisticated social engineering campaign to compromise organizations using the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool. Dubbed Smoke#Screen by security researchers at Securonix, this campaign takes advantage of diverse social engineering lures and rotating payloads to deliver persistent remote access to compromised networks.
The attackers are targeting both Windows and macOS systems with a range of lures, including purported Zoom and Adobe updates, business document requests, and system-maintenance tools. Victims who execute the initial access files end up with a fully functional ScreenConnect agent silently installed on their system, providing the threat actor with persistent remote access to compromised hosts.
What sets Smoke#Screen apart is its use of rotating payloads and varied social engineering lures. While it’s common for attackers to rotate malware payloads, the attacker’s practice of changing them between individual download sessions is unusual. The campaign also employs four different psychological contexts, rather than recycling variations of one theme, demonstrating a level of sophistication.
The researchers at Securonix discovered that attackers likely used a wide range of lures to maximize the population of potential victims and actively rotated payload hashes below download sessions to evade detection. By tracking the attack infrastructure and analyzing collected samples, the researchers were able to reconstruct five distinct kill chains and identify three separate ScreenConnect relay servers.
One of the most interesting aspects of this campaign is that it exposed much of its attack process, allowing the researchers to investigate comprehensively. The attackers left their C# source code sitting on an open directory next to compiled builds, giving the researchers a clear view of their development process. This visibility revealed features getting added between versions, two binaries turning out to be the same file with different names, and the use of various services like Dropbox for reputation and Cloudflare for anonymity.
The Smoke#Screen campaign demonstrates the evolving nature of threat actor playbooks, where attackers continually adapt and refine their tactics to evade detection. This campaign highlights the importance of staying vigilant and up-to-date with security controls, as well as the need for robust incident response planning to mitigate the impact of such attacks.
For organizations using ScreenConnect or similar RMM tools, it’s essential to implement robust security measures to prevent compromise. This includes ensuring that all software is kept up-to-date, using secure protocols for remote access, and regularly monitoring system logs for suspicious activity. By taking proactive steps to protect against these types of threats, organizations can reduce their risk of being compromised by sophisticated attackers like those behind the Smoke#Screen campaign.
Source: Dark Reading — 2026-08-04