Cyberattackers have launched a sophisticated social engineering campaign to compromise organizations via the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool. Dubbed “Smoke#Screen” by security researchers at Securonix, this attack takes the RMM playbook to new frontiers, exposing a threat actor’s playbook in the process.
The campaign uses diverse social engineering lures, including purported Zoom and Adobe updates, business document requests, and system-maintenance tools, to deliver ScreenConnect for persistent remote access to compromised networks. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers. This allows the threat actor to gain legitimate-looking remote access to compromised hosts.
What makes Smoke#Screen distinctive is its evolution over time, says Aaron Beardslee, manager of threat research at Securonix. The campaign relies on a toolkit of various droppers, loaders, and executables that ultimately point to a live staging server. While rotating malware payloads has become common practice among attackers, the use of four psychologically different contexts in the lures used to hook victims is unusual. These contexts include targeting consumer habits on unmanaged or bring-your-own-device (BYOD) systems, exploiting routine enterprise email behavior, and using a “SystemCheck” maintenance-tool lure that appears legitimate.
The attack’s lure strategy is designed to maximize the population of potential victims, with attackers likely using a wide swath of lures to achieve this goal. Moreover, they actively rotated payload hashes below download sessions to make hash-based detection ineffective across multiple investigative sampling periods. This sophistication and adaptability demonstrate the evolving nature of cyber threats.
Securonix’s investigation into Smoke#Screen began with a single VBScript dropper submitted to their telemetry, which led them to an active staging server hosting a full arsenal of 15 unique payloads. By mapping the infrastructure and performing analysis on all collected samples, the researchers reconstructed five distinct kill chains, identified three separate ScreenConnect relay servers, and documented how the actor’s techniques evolved from their earliest cautious samples to their current most aggressive configuration.
What allowed the researchers to investigate so comprehensively is that the attackers exposed much of their attack process. “They left their C# source code sitting on an open directory next to the compiled builds, so we didn’t have to guess at their development process, we could read it,” Beardslee explains. This visibility also revealed features getting added between versions, two binaries turning out to be the same file with different names, and the use of various tools for reputation, anonymity, and signing.
The Smoke#Screen campaign serves as a reminder that even legitimate tools can be abused by attackers. It’s essential for organizations to remain vigilant and regularly update their security controls to stay ahead of evolving threats. Furthermore, it highlights the importance of proper OpSec (operational security) practices, including secure coding and testing, to prevent exposing sensitive information. By staying informed about emerging threats and taking proactive measures, organizations can minimize the risk of falling victim to sophisticated attacks like Smoke#Screen.
Source: Dark Reading — 2026-08-04