top of page

SMOKE#SCREEN Campaign: Impersonating Zoom and Adobe updates to hijack computers

Information security researchers have recently discovered a dangerous cyberattack campaign named SMOKE#SCREEN. By spreading fake software update notifications from familiar applications like Zoom or Adobe, attackers can silently install remote control tools and gain full control over victims' computers.

Sophisticated decoys masquerading as familiar applications

The SMOKE#SCREEN campaign operates by deceiving users through common workplace decoys: Zoom and Adobe update notifications, requests to review business documents, or system maintenance notices.

The initial intrusion vector often originates from targeted phishing emails (spear-phishing). To bypass corporate cybersecurity filters that are typically very strict, attackers uploaded malicious scripts to the Dropbox storage service – a reputable platform commonly on allowed access lists. When users click on the phishing page zoom-update.html or attached files, the malware downloading process is officially triggered.

Exploiting legitimate management software to stay hidden

The ultimate goal of all attack scenarios in this campaign is to successfully install ConnectWise ScreenConnect – a Remote Monitoring and Management (RMM) tool widely used by IT technicians.

Exploiting legitimate software provides attackers with a major advantage. Instead of having to install Remote Access Trojans (RAT) that are easily detected by security systems, using ScreenConnect allows hacker traffic to blend in completely with routine network administration activities. Once ScreenConnect is successfully installed and connects back to the command server, attackers can easily open a remote access session to operate on the victim's computer at any time.

smoke-screen-campaign-fakes-zoom-and-adobe-updates
SMOKE#SCREEN Campaign fakes Zoom and Adobe updates

Technical tactics to bypass defense layers

According to research from Securonix Threat Research (conducted by experts Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee), this campaign employs several highly complex evasion techniques:

  • Checking analysis environment: Prior to execution, the initial VBScript automatically checks the list of running processes. If it detects system monitoring tools or virtual machine software (such as Wireshark, Process Monitor, VirtualBox, VMware Tools, XenServer, or Fiddler Classic), the malware immediately terminates execution to avoid analysis.

  • Disabling Windows security features: In certain variants, batch scripts are launched to disable the Antimalware Scan Interface (AMSI) in Windows, elevate administrative privileges via User Account Control (UAC) dialogs, disable SmartScreen protection in the Registry, and delete the downloaded file source attribute (Zone.Identifier) on MSI files.

  • Concealing servers using Cloudflare: Attackers leverage the Cloudflare Quick Tunnel service (via the cloudflared.exe tool)  to create temporary tunnels, hiding the location of the host server storing malicious files and maintaining command connections over port 8041.

An escalating technical arms race between two sides

The research team noted that the operational methods of the SMOKE#SCREEN campaign resemble a real-time "arms race" between attackers and defenders.

Initially, the actors behind the campaign used simple VBScript scripts encrypted with the XOR algorithm. Later, they transitioned to aggressive 9-step scripts designed to disable Windows Defender. Most recently, the group reverted to a stealthier tactic by optimizing evasion windows against Endpoint Detection and Response (EDR) systems and packaging malware into self-contained encrypted files. Currently, this activity has not been attributed to any specific hacker group or cybercrime organization.

Security recommendations for organizations

To protect IT infrastructure against attacks from the SMOKE#SCREEN campaign, cybersecurity experts recommend that organizations immediately implement the following measures:

  • Tighten installation privileges: Restrict permissions to arbitrarily execute .MSI installer files of unknown origin on employee computers.

  • Monitor system tampering behavior: Establish alert mechanisms when processes attempt to modify or disable security software.

  • Audit RMM tools: Regularly review internal usage of remote management software to ensure only authorized tools are operating.

  • Track anomalous command lines: Closely monitor unusual process executions originating from PowerShell or system command cmd.exe.

  • Apply strict UAC policies: Configure strict user permission assignments to prevent standard accounts from self-elevating to administrative privileges.

The high level of flexibility and continuous technical adaptation of the SMOKE#SCREEN campaign demonstrate that cybercriminals are investing heavily in evasive tactics to blind information security systems. Remaining vigilant when receiving files or software update links continues to be the first and most critical line of defense for all users.

Reference: The Hacker News

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page