SMOKE#SCREEN is a campaign that turns ordinary software updates and business files into a doorway for remote control.
Victims who run the files can unknowingly install a legitimate remote-management agent, giving an outside operator access to their computer.
The operation targets both Windows and macOS, widening the risk beyond one type of workplace device.
Its lures include supposed Zoom updates, document reviews, system checks and Adobe-related downloads, making routine work messages and update prompts part of the attack surface.
Securonix researchers identified the campaign and named it SMOKE#SCREEN after tracing several waves of activity to a shared delivery setup.
Securonix said in a report shared with Cyber Security News (CSN) that the goal is to install ScreenConnect quietly, then use it for remote access that can resemble normal IT support activity.
The campaign abuses ScreenConnect, a legitimate remote monitoring and management, or RMM, program.
That distinction matters: the tool itself is not malicious, but an attacker-controlled installation can hand over desktop control, file access and a foothold for follow-on activity without the obvious signals of conventional malware.
Investigators found the actors combined scripts, batch files, compiled loaders and a fake web page to deliver the agent.
Their staging setup also used Cloudflare Quick Tunnels, temporary routes that can obscure where a download is truly hosted, echoing earlier Cloudflare Tunnel delivery campaigns that used short-lived infrastructure to hide payloads.
A notable feature is the campaign’s cross-platform design. A macOS installer was configured to contact the same primary relay as Windows payloads, suggesting the operators can pursue users across mixed-device environments rather than treating Apple systems as an afterthought.
The operation also changes its files frequently, limiting the value of simple hash blocking.
Researchers observed multiple relay clusters and a server that both staged payloads and handled remote connections, a separation that can help an operator retain access even if part of the infrastructure is discovered.
The social engineering is equally important. One web page copied a Zoom update notice and automatically started a download after a short delay, while another posed as an Adobe Flash Player update.
These familiar-looking prompts can move a victim from a single click to a silent RMM installation with little visible warning.
This technique fits a broader pattern of trusted RMM tool phishing, where legitimate administration software becomes the final payload.
For defenders, the key question is not only whether a file looks malicious, but whether a newly installed remote-access tool is approved, expected and connecting to a known service.
SMOKE#SCREEN developed from heavily obscured scripts into more forceful loaders that attempted to weaken Windows protections before delivery.
One sequence targeted security scanning, elevation controls and endpoint settings, while also removing downloaded files after installation, reducing the traces left for users and analysts.
Later activity showed a quieter approach. The operators replaced the most aggressive security-disabling behavior with a deliberate delay between installation and service start, apparently intended to break security-product event correlation.
That evolution shows why detections should consider a chain of related actions, not just a single suspicious file.
Organizations should restrict untrusted MSI installers from common user-writable folders, keep User Account Control at its strictest setting, and alert on attempts to stop security services or create broad antivirus exclusions.
Monitoring unusual script-to-installer launches, particularly PowerShell or command shell processes starting silent installations, can expose the chain early.
Teams should also inventory approved RMM software and block unauthorized clients and network connections, especially those using direct internet addresses rather than recognised service domains.
This is consistent with guidance in recent ScreenConnect abuse coverage, which stresses that phishing can turn legitimate remote-management functions into covert access.
Finally, security staff should investigate unexpected changes to Defender settings and short delays following an installer launch.
Pairing those checks with Defender tampering detection guidance gives analysts better context for separating ordinary support activity from an attempted takeover.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address and ports | 207.174.0.143:8080, 207.174.0.143:8041 | WsgiDAV staging server and primary ScreenConnect relay |
| IP address and ports | 142.202.191.225:8041, 142.202.191.225:80 | Secondary ScreenConnect relay |
| Domain and port | blog.derrspecial-onlinedmin.live:8041 | Tertiary ScreenConnect relay |
| IP address | 207.189.11.170 | Former C# payload hosting |
| URL | 207.189.11.170/Bin/working_payload.cs | Remote C# payload location |
| Domain | crestmarkhq.com | Former Cloudflare-proxied MSI hosting |
| Domain | subscription-magnetic-recommended-meat.trycloudflare.com | Cloudflare Quick Tunnel used for MSI delivery |
| IP addresses | 104.16.231.132, 104.16.230.132 | Resolved addresses for the Cloudflare Quick Tunnel |
| URL path | dropbox.com/scl/fi/a0hp9g4w2ddkb3ggnkivx/ | Dropbox-hosted installer delivery path |
| File and SHA-256 | zoom-update.vbs / 9161a8f7f07741db06b9f9a87b6ec7f277faf2ae3a3a661d6eb09cec4e12b920 | Obfuscated VBScript dropper |
| File and SHA-256 | RSKAdvGrpSupportingdocuments.vbs / 35be1b070f06eb313c3cb818c74aa0a9c2d9f39a05621dac4de6cff6067a5d12 | Business-document themed VBScript dropper |
| File and SHA-256 | SystemCheck / 31260c37cc442719ac84540f4159dd9d4738575d2ab05e92c751a9b4b5f9b91b | Security-disabling batch loader |
| File | SystemCheck.gzip | Archive used to deliver the SystemCheck loader |
| File | SystemCheck.msi | ScreenConnect MSI payload |
| File and SHA-256 | MemoryLoader.cs / 371166ebd83e8318b49ba71321396524fbca7dc42fe1ca4badda8af794bf5a59 | C# source for compiled loader variants |
| File and SHA-256 | zoom-update.html / 873011c181d00709fdf66f32bb3cca0c5ff3147d00ef818fef72987a6773ea66 | Zoom-themed phishing page |
| File and SHA-256 | AdobeReader_Update.exe / 433b61c29aefaa5b55fe78063e6ad8597d3835f36e1242d5402ab23e6dc61194 | Renamed compiled loader |
| File | lirMkvpf.exe | Internal name of AdobeReader_Update.exe loader |
| File and SHA-256 | NYbiLtvO.exe / c8695906dcefc64becb3123fa0a8058278c8c2f9c86130956b6b10d49c1a35dc | Earlier compiled loader build |
| File and SHA-256 | BuYUEVqG.msi / 8e87a734daddd95322b3f18f71eb9275219e244aac4f62b8dc6da6e2e91525e9 | Primary-cluster ScreenConnect MSI |
| File | JqbMljCi.msi | Randomly named MSI delivered through Cloudflare Quick Tunnel |
| File and SHA-256 | Zoomupdateinstaller.msi / dd23012b4dc29cf7901185ae4fb2d507e737e9ea4d467846eafd6a86b26486bf | Zoom-themed Windows MSI payload |
| File and SHA-256 | Document-review.msi / 3cd9b7d583442963261f9985128042bf45d25482efcbf903c9248837cb0d744b | Secondary-cluster ScreenConnect MSI |
| File and SHA-256 | DocumentReview.msi / 01e4cb3c60fa50b2927daa11f25a3c412549680406fc121a3d1870a9a33f5d38 | Secondary-cluster ScreenConnect MSI |
| File and SHA-256 | SystemCheck.exe / 60c730addd2a15e4213a1d37f55186686976de73a106317b5a258fe0121cfd5c | Primary-cluster executable payload |
| File and SHA-256 | Document-Viewer.exe / dc8b056dd6eb75df21e9721ac2e340f91bb5e94d5a6ff412d7d0c7539e0f06e2 | Tertiary-cluster executable payload |
| File and SHA-256 | ZoomUpdateInstaller.pkg / aa84e2ac68f7fc18f4927b89be7b4a7739f2eaf099e489aa0f65c1d3913ce62a | macOS ScreenConnect installer |
| File and SHA-256 | cloudflared.exe / 5253e66f1f493c4e13539749f1aa86fd0c61e3072900fec29a44ba046a6d97e2 | Cloudflare tunnel binary on staging server |
| File | WindowsExplorerSupport.msi | Local masquerade name used for downloaded MSI |
| File and SHA-256 | loader.cs / 63c46b3c090a4b1efef146f2f1efc4f93d44f21db21d7825f43e02c3c5c89de6 | Updated stealth-focused loader source |
| Files and SHA-256 | zFbJVuiX.exe, Zoomupdateinstaller.exe / 9d9f3fa5aaf6bc91091873bd7ee04f0cc23e8709e4ad20c61d2779ff1a43c4b4 | Compiled loader and renamed copy |
| File and SHA-256 | Zoomupdateinstaller.pkg / 639430a33c0ecdf5a134501788a3a40f065ae4232efc66e1b82eca2b355e0606 | macOS payload variant |
| File and SHA-256 | index.html / 2423decbfcf820f41bc356547e4e18e61d60c9829421d7121c374dcef88577f7 | Adobe Flash Player-themed phishing page |
| File and SHA-256 | system.config / aefac65c42c0c72ed3e08b32774fa1b902f4fd1d53de189d50f38130cc357764 | Campaign configuration file |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…