Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
New Phishing-as-a-Service Kits Bypass MFA to Steal Microsoft 365 Logins
August 5, 2026
Critical TP-Link Omada ZTP Flaws Let Attackers Hijack Routers, Execute Root Code
August 5, 2026
Critical OVSwrap Linux Vulnerability (CVE-2024-3094) Lets Attackers Gain Root
August 5, 2026
Home/Threats/Critical ConnectWise ScreenConnect vulnerability allows macOS/Windows hijack
Threats

Critical ConnectWise ScreenConnect vulnerability allows macOS/Windows hijack

Key Takeaways The “SMOKE#SCREEN” campaign leverages seemingly legitimate software updates and business documents to deploy remote management tools. It targets both Windows and macOS...

Sarah simpson
Sarah simpson
August 5, 2026 3 Min Read
2 0

Key Takeaways

  • The “SMOKE#SCREEN” campaign leverages seemingly legitimate software updates and business documents to deploy remote management tools.
  • It targets both Windows and macOS systems, broadening its potential victim base across diverse work environments.
  • Attackers install the ConnectWise ScreenConnect remote monitoring and management (RMM) agent, enabling covert remote access that mimics legitimate IT support.
  • The campaign employs Cloudflare Quick Tunnels to obscure payload hosting and frequently changes file hashes to evade detection.
  • Security teams should prioritize monitoring for unauthorized RMM installations, unusual script executions, and suspicious network connections, alongside maintaining strict user access controls.

SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels

A sophisticated new campaign, dubbed “SMOKE#SCREEN” by researchers at Securonix, is actively exploiting user trust in routine software updates and business-related files to establish clandestine remote control over victim systems. This operation has successfully targeted both Windows and macOS devices, expanding its threat footprint across a wide spectrum of organizational endpoints.

Table Of Content

  • Key Takeaways
  • SMOKE#SCREEN Campaign Abuses ScreenConnect RMM and Cloudflare Tunnels
  • Deceptive Lures and Covert Delivery
  • Evolving Evasion Techniques
  • What You Should Do

The core of the SMOKE#SCREEN strategy involves tricking users into executing files that surreptitiously install ConnectWise ScreenConnect, a legitimate remote monitoring and management (RMM) agent. Once installed, this agent provides attackers with unauthorized access to the victim’s computer, including desktop control and file manipulation, often mimicking standard IT support activities, thereby evading immediate suspicion. Securonix said in a report detailing the campaign’s tactics, techniques, and procedures.

Deceptive Lures and Covert Delivery

The attackers employ various social engineering tactics to deliver their payloads. These include fake update prompts for popular applications like Zoom and Adobe Flash Player, as well as deceptive document review requests and system check utilities. These familiar-looking prompts are designed to induce victims into initiating a download and installation with minimal visible warnings.

Investigators discovered that the campaign’s delivery infrastructure combines various components, including scripts, batch files, custom-compiled loaders, and spoofed web pages. A critical element in their evasion strategy is the use of Cloudflare Quick Tunnels. These temporary, short-lived routes are leveraged to obscure the actual hosting location of the malicious payloads, making it challenging for defenders to trace the origin of the attack. This method echoes previous campaigns that utilized Cloudflare Tunnels to hide illicit activities.

A notable aspect of SMOKE#SCREEN is its cross-platform functionality. Researchers observed macOS installers configured to communicate with the same primary command-and-control (C2) relays as Windows payloads. This indicates a deliberate strategy by the operators to target users across mixed-device environments, rather than treating Apple systems as a secondary objective.

Evolving Evasion Techniques

The campaign’s operators frequently alter their files, rendering simple hash-based blocking ineffective. Furthermore, they utilize multiple relay clusters and separate servers for payload staging and remote connections. This architectural separation enhances their resilience, allowing them to maintain access even if parts of their infrastructure are compromised or detected.

Initially, SMOKE#SCREEN employed aggressive methods to disable Windows security features before payload delivery. These early versions targeted security scanning, User Account Control (UAC), and endpoint settings, often deleting downloaded files post-installation to minimize forensic traces. However, later iterations of the campaign demonstrated a shift towards stealthier techniques.

More recent activity shows attackers replacing overt security-disabling actions with a deliberate delay between the ScreenConnect installation and its service initiation. This delay is believed to be an attempt to break the event correlation mechanisms used by security products, making it harder to link the initial infection vector with the subsequent RMM activity. This evolution underscores the importance of analyzing a chain of related actions rather than focusing on isolated suspicious files.

What You Should Do

  • Restrict Untrusted Installations: Implement policies to prevent untrusted MSI installers from executing in common user-writable directories.
  • Maintain Strict UAC: Keep User Account Control (UAC) at its highest setting to require explicit user permission for administrative actions.
  • Monitor Security Service Tampering: Configure alerts for any attempts to stop security services or create broad antivirus exclusions.
  • Detect Unusual Script Execution: Monitor for unusual launches of installers via scripting languages like PowerShell or command shells, especially those performing silent installations.
  • Inventory and Block Unauthorized RMMs: Maintain a comprehensive inventory of approved RMM software. Block any unauthorized RMM clients and network connections, particularly those communicating with direct IP addresses instead of recognized service domains.
  • Investigate Defender Settings Changes: Promptly investigate any unexpected modifications to Windows Defender settings and short delays observed after an installer launch. Reference Defender tampering detection guidance for better context.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwarephishingSecurityThreatVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

EtherRAT Spreads via Scheduled Tasks in Compromised Windows Domains

Next Post

Django Patches Four High-Severity Vulnerabilities in Versions 6.0.8 and 5.2.17

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
EtherRAT Spreads via Scheduled Tasks in Compromised Windows Domains
August 5, 2026
7-Zip Mark-of-the-Web Bypass Lets Malicious Files Evade Windows SmartScreen
August 5, 2026
Microsoft Defender Stops QNET Ransomware Attack in 128 Seconds
August 5, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us