Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The Smoke#Screen campaign is a sophisticated social engineering attack leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically ScreenConnect, to gain persistent remote access to compromised networks. Threat actors are using a variety of lures – including fake Zoom and Adobe updates, document requests, and maintenance tool requests – to trick users into executing malicious files that install a full ScreenConnect agent. The campaign’s success stems from its rotating payloads, diverse lure strategies, and use of evasion techniques like Cloudflare tunnels and ConnectWise signatures, making traditional signature-based defenses ineffective. Securonix researchers were able to fully investigate the campaign due to the attackers’ openness, revealing a complex and adaptable threat actor.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
_Ivelin_Radkov_Alamy.png?width=720&quality=80&disable=upscale)