{"id":2202,"date":"2026-08-04T16:03:19","date_gmt":"2026-08-04T16:03:19","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2202"},"modified":"2026-08-04T16:03:19","modified_gmt":"2026-08-04T16:03:19","slug":"fake-adobe-and-zoom-updates-install-screenconnect-for-persistent-remote-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2202","title":{"rendered":"Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi35nnI5-o_HtA0Eunk4tOFM1lg12NrqY7HrDNBbee-kPWR-BHHxXQtd-Tj3b7FrMlTOcWNC63XgVV9n0FEoD-G4ydCpmBv2g1PjvS-lzopLbMnODHbNL2bGMJ6nOYXST9M83vc9IYZaUOjkUqaa4Xo-LaAOtXu3bRhYAcVIUwxgDNMifc6xWI27VVca_B4\/s1700-e365\/screenconnect.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.<\/p>\n<p>The campaign has been codenamed <b>SMOKE#SCREEN<\/b> by Securonix Threat Research.<\/p>\n<p>\u00abThe campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0[.]143:8080,\u00bb researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a <a href=\"https:\/\/www.securonix.com\/blog\/smoke-screen-screenconnect-rmm-abuse-cloudflare-tunnels\/\" target=\"_blank\">report<\/a> shared with The Hacker News.<\/p>\n<p>Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to compromised systems. The activity has not been attributed to any known threat actor or group.<\/p>\n<p>The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan.<\/p>\n<p>Securonix said its investigation commenced following the discovery of a live WsgiDAV server that served two purposes: stage malicious payloads and maintain command-and-control (C2) over existing infected machines through a ScreenConnect relay on port 8041.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/threatlocker-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh5OTk93vfDmhLLtqoMsx4w59kseqsUysQ92SKB-S2vDoKsMmMfCCkx8AbG5MFzFvZ7rkzKd5LtgOCxlRF2FJ-0FArsVhpOnTMX31VBi9TX-z1Pgv9oSvXiT23KyDlxtVqI0dPRdMIuWc9fbNWgQF8CisKtMme0LpNr79b4wRaeDRxCjfGB8GsxfXa8Ltro\/s728-e100\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>An analysis of the ScreenConnect relay configuration strings embedded in the MSI and EXE payloads has uncovered three distinct C2 clusters, each associated with software update, document review, and document viewer decoy binaries.<\/p>\n<p>The initial access vector is assessed to be spear-phishing, with the emails serving as a conduit for an obfuscated Visual Basic Script (aka VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes, and aborts if any of the following executables are running &#8211;<\/p>\n<ul>\n<li>Wireshark (wireshark.exe)<\/li>\n<li>Process Monitor (procmon.exe)<\/li>\n<li>Oracle VM VirtualBox (vboxservice.exe)<\/li>\n<li>Broadcom VMware Tools (vmtoolsd.exe)<\/li>\n<li>Citrix XenServer (xenservice.exe)<\/li>\n<li>Fiddler Classic (fiddler.exe)<\/li>\n<\/ul>\n<p>If the environment checks pass, the script proceeds to decrypt a PowerShell command that fetches a C# payload from \u00ab207.189.11[.]170\u00bb and executes it. Alternatively, attacks have been observed using business-themed lures to trick recipients into running a VBScript that ultimately leads to ScreenConnect installation.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>A third sample linked to the activity is delivered as a compressed archive, from which a batch script is run to disable Windows Antimalware Scan Interface (AMSI), escalate privileges by means of a User Account Control (UAC) prompt, turn off SmartScreen protections via Registry modifications, and then remove the Zone.Identifier alternate data stream (ADS) from the downloaded MSI file before running it.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj_EY8skrKXmsu5XkbZKEbH2BmMz-YnJF2Moj0NrrjnCclyeRJt_3f4pyTW8zPm7UhrGBx7XtffP89NZxjRbG7XhvJOHrbc0JuvgsTcu31YLZV5pPyw544o6nYaKQkalcrVn1xy3rcJDRMq4oyJy3YOhfzYmW4n7KhbFSY2eeuL_Msd90mUIZVDKZgZ5Lbr\/s1700-e365\/ZOOM.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj_EY8skrKXmsu5XkbZKEbH2BmMz-YnJF2Moj0NrrjnCclyeRJt_3f4pyTW8zPm7UhrGBx7XtffP89NZxjRbG7XhvJOHrbc0JuvgsTcu31YLZV5pPyw544o6nYaKQkalcrVn1xy3rcJDRMq4oyJy3YOhfzYmW4n7KhbFSY2eeuL_Msd90mUIZVDKZgZ5Lbr\/s1700-e365\/ZOOM.png\" alt=\"\" border=\"0\" data-original-height=\"1098\" data-original-width=\"1857\"\/><\/a><\/div>\n<p>\u00abThe actor&#8217;s delivery strategy has also rotated across multiple trusted hosting services,\u00bb Securonix said. \u00abAn early phishing page (&#8216;zoom-update.html&#8217;) delivers its payload via a Dropbox shared link, bypassing domain reputation filters since Dropbox is an allow-listed platform in most corporate environments.\u00bb<\/p>\n<p>\u00abA compiled .NET loader (&#8216;MemoryLoader.cs&#8217;) references a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com), a service designed for temporary local server exposure that is rarely monitored. The staging server itself runs cloudflared.exe, confirming that the actor uses the Cloudflare binary directly on their infrastructure to generate these ephemeral tunnels.\u00bb<\/p>\n<p>Irrespective of the phishing lure used, all attack paths lead to the same destination: the installation of ScreenConnect client, which connects to a configured relay server and allows the operator to open a remote desktop session with the victim&#8217;s machine.<\/p>\n<p>\u00abWhat makes this campaign particularly notable for defenders is the observable arc of the actor&#8217;s tradecraft,\u00bb Securonix said. \u00abFrom cautious XOR-encrypted VBScript droppers to aggressive nine-step Defender destruction sequences and then, most recently, a pivot back to stealth with anti-EDR timing and self-contained encrypted bundles, the campaign reads like a real-time arms race between attacker and defender.\u00bb<\/p>\n<p>To counter the threat, organizations are recommended to restrict execution of untrusted MSI files, monitor when processes attempt to tamper with security products, audit legitimate use of RMM tools, check for suspicious PowerShell and \u00abcmd.exe\u00bb processes, and enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks.<\/p>\n<h3>Fake Xeno Roblox Cheats Deliver Java Stealer Malware<\/h3>\n<p>The disclosure comes as Bitdefender <a href=\"https:\/\/www.bitdefender.com\/en-us\/blog\/labs\/fake-xeno-roblox-discord-executor\" target=\"_blank\">warned<\/a> of a separate campaign in which fake Xeno Executor installers promoted via gaming forums and Discord communities are used to initiate a multi-stage Java infection chain that drops an information stealer capable of credential theft, as well as stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.<\/p>\n<p>The stealer, named <a href=\"https:\/\/www.threatlocker.com\/blog\/powercat-malware-campaign-fake-game-cheats-deliver-infostealer-targeting-discord-roblox-and-crypto-wallets\" target=\"_blank\">Powercat<\/a>, can also record keystrokes, access the webcam, stream the victim&#8217;s desktop, manipulate files, run PowerShell commands, and grant attackers interactive control of the infected computer.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizpljoIT6VDwNl18oARTx1Nu0gPvgtRPHWKDmtlXYhyphenhyphenZhHRTjSx4i1k1S9WvmjnBCnA507wiRsBU4BcWMsOvytwtKwzOH0xVSFIjTFVgXnhYbp9eAggoH_iDI3bAfEOGsdLrQbBEOpZv2aBblGnaSKCC8T3uiBlgfjlVCqDoKxY9-Ao8f_frZ1hl9EP-us\/s1700-e365\/KILL.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizpljoIT6VDwNl18oARTx1Nu0gPvgtRPHWKDmtlXYhyphenhyphenZhHRTjSx4i1k1S9WvmjnBCnA507wiRsBU4BcWMsOvytwtKwzOH0xVSFIjTFVgXnhYbp9eAggoH_iDI3bAfEOGsdLrQbBEOpZv2aBblGnaSKCC8T3uiBlgfjlVCqDoKxY9-Ao8f_frZ1hl9EP-us\/s1700-e365\/KILL.jpg\" alt=\"\" border=\"0\" data-original-height=\"601\" data-original-width=\"900\"\/><\/a><\/div>\n<p>\u00abThe final payload combines information theft, surveillance, persistence, remote access, file manipulation and command execution,\u00bb Bitdefender researchers Janos Gergo Szeles and Silviu Stahie said.<\/p>\n<p>The activity is believed to have been ongoing since the start of 2026, with a surge recorded in the second half of March. Some aspects of the campaign were previously documented by ThreatLocker in late March 2026, highlighting the threat actor&#8217;s use of bogus cheats for popular PC games to distribute Powercat.<\/p>\n<p>The so-called cheats come in the form of archives that mimic a legitimate Xeno installation using plausible file names. Victims are instructed to run a \u00abxeno.exe,\u00bb which, instead of launching the cheat, runs the first stage of the malware.<\/p>\n<p>The payload checks for a Java Runtime Environment, extracts one if missing, and then reads a local file (\u00abXenoIcon.jpg\u00bb) containing the keys necessary to validate its execution with the C2 server (\u00absolthere[.]net\u00bb). Subsequently, it launches an obfuscated JAR file disguised as \u00abdecompiler.exe,\u00bb which performs environment checks, registers the victim, and downloads the final malware payload.<\/p>\n<p>The third stage is a Java-based stealer and surveillance malware that can harvest sensitive data, collect screenshots and webcam footage, stream the victim&#8217;s desktop, and monitor keyboard and mouse activity. It can also download and upload files, execute commands through PowerShell, and open an interactive shell for hands-on-keyboard access, giving the attacker full control over the host.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abPersonal information theft begins with the malware gathering information about potentially interesting software installed on the victim&#8217;s system,\u00bb Bitdefender said. \u00abThis allows the operators to adapt their strategy and prioritize which data to steal.\u00bb<\/p>\n<p>Targeted applications include &#8211;<\/p>\n<ul>\n<li>Web browsers (Brave Browser, Chrome, Edge, Opera, Opera GX, and Vivaldi)<\/li>\n<li>Cryptocurrency wallets (Atomic, Cake Wallet, Exodus, Monero Wallet, SafePal, and Tron Wallet)<\/li>\n<li>Software development tools (Git, JetBrains tools, Microsoft Visual Studio, and Python IDLE)<\/li>\n<li>Game launchers (Battle.net, Epic Games Launcher, Riot Client, Rockstar Games Launcher, and Steam)<\/li>\n<li>VPN (ExpressVPN, Mullvad VPN, NordVPN, and Surfshark)<\/li>\n<li>Messengers (Discord, Snapchat, Telegram, and WhatsApp)<\/li>\n<li>Roblox and Minecraft installations (Feather, Lunar, Meteor, Modrinth, Prism, and the official Minecraft launcher)<\/li>\n<\/ul>\n<p>To target Exodus cryptocurrency wallets, the stealer checks if Exodus version 26.1.5 is installed on the system, and, if so, unpacks the \u00abapp.asar\u00bb archive and injects JavaScript code to capture valid tokens and exfiltrate them to the C2 server.<\/p>\n<p>\u00abGaming-related lures remain effective because they exploit users&#8217; interest in gaining an advantage, accessing restricted functionality, or avoiding anti-cheat detection,\u00bb Bitdefender said.<\/p>\n<p>\u00abThe delivered malware is considerably more capable than a typical credential stealer. Its remote-access and command-execution capabilities also mean that the compromise can continue beyond the initial theft of information, which can lead to data destruction or allow operators to use the infected system in other cyber-criminal activities.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2203,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,1135,150,1779,646,12,863,619,2558],"class_list":["post-2202","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-adobe","tag-fake","tag-install","tag-persistent","tag-remote","tag-screenconnect","tag-updates","tag-zoom"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2202"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2202\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2203"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}