Fake Adobe, Zoom Updates Install ScreenConnect for Remote Access

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Cybersecurity researchers disclosed an active, multi-wave campaign that uses social engineering lures themed around fake Adobe and Zoom software updates to stealthily deploy Remote Monitoring and Management (RMM) programs.
- Attackers also use lures themed around business document reviews and system maintenance utilities, with the goal of installing tools such as ScreenConnect to gain persistent remote access to victim machines.
Why it matters: By weaponizing legitimate RMM software like ScreenConnect through convincing fake update prompts, attackers gain persistent remote access that blends in with normal IT activity, making detection harder for defenders and putting any organization whose users handle routine updates at risk.


