Fake Updates Hide a Legitimate Remote Access Backdoor

The risk is not a classic malware implant. The attacker ends with a legitimate ScreenConnect agent, so the compromise can look like approved remote support and slip past normal malware hunting. Fake Adobe and Zoom update prompts, document lures, and maintenance themes are just the path to that outcome. Securonix says SMOKE#SCREEN is an active, multi-wave campaign that installs ConnectWise ScreenConnect through droppers and loaders, then connects the agent to attacker-controlled relays for persistent access. The abuse matters because ScreenConnect is real IT tooling, so the control channel blends into ordinary administration traffic instead of standing out as a rogue remote-access trojan. That shifts the defender's job from finding obvious malware to finding unauthorized use of trusted remote-management software. Any environment that allows user-driven software-update prompts or remote support tools can be pulled into the same lure pattern, even without ScreenConnect itself.

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: Fake Updates Hide a Legitimate Remote Access Backdoor

Sources