✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved

Fake Adobe and Zoom Updates Deploy ScreenConnect RAT

By The Hacker News · Summarized & edited by · 2026-08-04
Fake Adobe and Zoom Updates Deploy ScreenConnect RAT

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: SMOKE#SCREEN exploits the abuse of legitimate RMM tools like ScreenConnect—which are common in enterprise environments—letting attackers blend in with authorized IT tooling without deploying a custom RAT. With the campaign's tradecraft visibly evolving through an attacker-defender arms race (from XOR-encrypted VBScript to Defender destruction sequences to anti-EDR stealth), IT and SOC teams must now audit and monitor trusted RMM activity as a core detection priority, not assume allow-listed tools are inherently safe.

Share this story

Ask SkimNews
More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.