Critical ConnectWise ScreenConnect vulnerability allows macOS/Windows hijack
Key Takeaways The “SMOKE#SCREEN” campaign leverages seemingly legitimate software updates and business documents to deploy remote management tools. It targets both Windows and macOS...
Key Takeaways
- The “SMOKE#SCREEN” campaign leverages seemingly legitimate software updates and business documents to deploy remote management tools.
- It targets both Windows and macOS systems, broadening its potential victim base across diverse work environments.
- Attackers install the ConnectWise ScreenConnect remote monitoring and management (RMM) agent, enabling covert remote access that mimics legitimate IT support.
- The campaign employs Cloudflare Quick Tunnels to obscure payload hosting and frequently changes file hashes to evade detection.
- Security teams should prioritize monitoring for unauthorized RMM installations, unusual script executions, and suspicious network connections, alongside maintaining strict user access controls.
SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels
A sophisticated new campaign, dubbed “SMOKE#SCREEN” by researchers at Securonix, is actively exploiting user trust in routine software updates and business-related files to establish clandestine remote control over victim systems. This operation has successfully targeted both Windows and macOS devices, expanding its threat footprint across a wide spectrum of organizational endpoints.
Table Of Content
The core of the SMOKE#SCREEN strategy involves tricking users into executing files that surreptitiously install ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) agent. Once installed, this agent provides attackers with unauthorized access to the victim’s computer, including desktop control and file manipulation, often mimicking standard IT support activities, thereby evading immediate suspicion. Securonix said in a report detailing the campaign’s tactics, techniques, and procedures.
Deceptive Lures and Covert Delivery
The attackers employ various social engineering tactics to deliver their payloads. These include fake update prompts for popular applications like Zoom and Adobe Flash Player, as well as deceptive document review requests and system check utilities. These familiar-looking prompts are designed to induce victims into initiating a download and installation with minimal visible warnings.
Investigators discovered that the campaign’s delivery infrastructure combines various components, including scripts, batch files, custom-compiled loaders, and spoofed web pages. A critical element in their evasion strategy is the use of Cloudflare Quick Tunnels. These temporary, short-lived routes are leveraged to obscure the actual hosting location of the malicious payloads, making it challenging for defenders to trace the origin of the attack. This method echoes previous campaigns that utilized Cloudflare Tunnels to hide illicit activities.
A notable aspect of SMOKE#SCREEN is its cross-platform functionality. Researchers observed macOS installers configured to communicate with the same primary command-and-control (C2) relays as Windows payloads. This indicates a deliberate strategy by the operators to target users across mixed-device environments, rather than treating Apple systems as a secondary objective.
Evolving Evasion Techniques
The campaign’s operators frequently alter their files, rendering simple hash-based blocking ineffective. Furthermore, they utilize multiple relay clusters and separate servers for payload staging and remote connections. This architectural separation enhances their resilience, allowing them to maintain access even if parts of their infrastructure are compromised or detected.
Initially, SMOKE#SCREEN employed aggressive methods to disable Windows security features before payload delivery. These early versions targeted security scanning, User Account Control (UAC), and endpoint settings, often deleting downloaded files post-installation to minimize forensic traces. However, later iterations of the campaign demonstrated a shift towards stealthier techniques.
More recent activity shows attackers replacing overt security-disabling actions with a deliberate delay between the ScreenConnect installation and its service initiation. This delay is believed to be an attempt to break the event correlation mechanisms used by security products, making it harder to link the initial infection vector with the subsequent RMM activity. This evolution underscores the importance of analyzing a chain of related actions rather than focusing on isolated suspicious files.
What You Should Do
- Restrict Untrusted Installations: Implement policies to prevent untrusted MSI installers from executing in common user-writable directories.
- Maintain Strict UAC: Keep User Account Control (UAC) at its highest setting to require explicit user permission for administrative actions.
- Monitor Security Service Tampering: Configure alerts for any attempts to stop security services or create broad antivirus exclusions.
- Detect Unusual Script Execution: Monitor for unusual launches of installers via scripting languages like PowerShell or command shells, especially those performing silent installations.
- Inventory and Block Unauthorized RMMs: Maintain a comprehensive inventory of approved RMM software. Block any unauthorized RMM clients and network connections, particularly those communicating with direct IP addresses instead of recognized service domains.
- Investigate Defender Settings Changes: Promptly investigate any unexpected modifications to Windows Defender settings and short delays observed after an installer launch. Reference Defender tampering detection guidance for better context.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.