Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
A multi-wave campaign leveraging social engineering to deploy Remote Monitoring and Management (RMM) software, specifically ScreenConnect, is actively targeting users with fake Adobe and Zoom updates, as well as business document review and viewer lures. The campaign employs a sophisticated toolkit of VBScript droppers, batch file loaders, and compiled .NET executables to bypass security controls and gain persistent remote access to compromised systems. Researchers have observed a progression of tactics, from initial dropper obfuscation to aggressive Defender destruction sequences and now, a return to stealth with anti-EDR timing and self-contained encrypted bundles. Simultaneously, Bitdefender has identified a separate campaign distributing a Java-based stealer named Powercat through fake Xeno Roblox cheats, designed to steal sensitive data from various applications and services, including web browsers, cryptocurrency wallets, and gaming platforms.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
