Fake Adobe and Zoom Updates Deploy ScreenConnect RAT

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Securonix Threat Research disclosed a multi-wave campaign codenamed SMOKE#SCREEN that uses fake Adobe and Zoom update lures, business document reviews, and system maintenance themes to deploy ConnectWise ScreenConnect, with payloads staged through a WsgiDAV server at 207.174.0[.]143:8080.
- The initial access vector is spear-phishing emails carrying obfuscated VBScript droppers that perform anti-analysis checks, aborting if processes like Wireshark, Process Monitor, VirtualBox, VMware Tools, XenServer, or Fiddler are detected before fetching a C# payload from 207.189.11[.]170.
- A third attack sample runs a batch script to disable Windows AMSI, escalate privileges via UAC, turn off SmartScreen protections through Registry modifications, and strip the Zone.Identifier alternate data stream before executing the MSI installer.
- The campaign's tradecraft rotated across trusted hosting services including Dropbox shared links and Cloudflare Quick Tunnels, and evolved from cautious XOR-encrypted VBScript droppers to aggressive nine-step Defender destruction sequences and then back to stealth with anti-EDR timing and self-contained encrypted bundles.
- Separately, Bitdefender warned of a campaign using fake Xeno Roblox cheat installers promoted via gaming forums and Discord to deliver Powercat, a Java-based stealer active since early 2026 with a surge in March, capable of harvesting credentials, browser cookies, Discord/Roblox/Minecraft accounts, and crypto-wallet data.
- Powercat goes beyond credential theft by recording keystrokes, accessing the webcam, streaming the victim's desktop, manipulating files, running PowerShell commands, and granting interactive remote control, targeting browsers (Brave, Chrome, Edge, Opera, Opera GX, Vivaldi), wallets (Atomic, Exodus, Monero, SafePal, Tron), and tools like Git, JetBrains, Visual Studio, and Steam.
- Securonix recommends organizations restrict untrusted MSI execution, monitor processes tampering with security products, audit legitimate RMM tool usage, flag suspicious PowerShell and cmd.exe activity, and enforce strict UAC settings to prevent bypass of admin prompts.
Why it matters: SMOKE#SCREEN exploits the abuse of legitimate RMM tools like ScreenConnect—which are common in enterprise environments—letting attackers blend in with authorized IT tooling without deploying a custom RAT. With the campaign's tradecraft visibly evolving through an attacker-defender arms race (from XOR-encrypted VBScript to Defender destruction sequences to anti-EDR stealth), IT and SOC teams must now audit and monitor trusted RMM activity as a core detection priority, not assume allow-listed tools are inherently safe.
Ask SkimNews


