Ethical Hacking News
Threat Landscape Alert: Sophisticated campaigns utilizing social engineering tactics are deploying Remote Monitoring and Management (RMM) tools and delivering malware. Organizations must take immediate action to protect themselves against these threats by implementing measures such as restricting untrusted MSI file execution, monitoring suspicious processes, and enforcing strict UAC settings.
Sophisticated social engineering campaign using Adobe and Zoom software updates, business document reviews, and system maintenance utilities to deploy RMM tools and deliver malware. Uses a toolkit of VBScript droppers, batch file loaders, compiled .NET executables, and an HTML phishing page to deliver the malware. Installs ScreenConnect agent, which connects to attacker-controlled relay servers for persistent remote access to compromised systems. Spear-phishing emails serve as a conduit for obfuscated VBScript droppers that check for safe execution and enumerate running processes. Business-themed lures trick recipients into running a VBScript leading to ScreenConnect installation. Legitimate RMM tools are used to bypass security controls and blend in with authorized IT tooling. A separate campaign uses fake installers to initiate a multi-stage Java infection chain that drops an information stealer capable of stealing credentials, browser accounts, and payment information. The information stealer (Powercat) can record keystrokes, access the webcam, stream the desktop, manipulate files, run PowerShell commands, and grant attackers interactive control of the infected computer.
A recent threat intelligence report has shed light on a sophisticated campaign that leverages social engineering tactics to deploy Remote Monitoring and Management (RMM) tools and deliver malware. The campaign, codenamed SMOKE#SCREEN by Securonix Threat Research, has been observed employing various vectors, including Adobe and Zoom software updates, business document reviews, and system maintenance utilities.
The attackers use a toolkit of VBScript droppers, batch file loaders, compiled .NET executables, and an HTML phishing page to deliver the malware. The malicious payload ultimately leads to the installation of ScreenConnect agent, which connects to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to compromised systems.
The campaign relies on spear-phishing as the initial access vector, where the emails serve as a conduit for an obfuscated Visual Basic Script (VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes and aborts if any of certain executables are running.
Furthermore, the attackers use business-themed lures to trick recipients into running a VBScript that ultimately leads to ScreenConnect installation. A third sample linked to the activity is delivered as a compressed archive, from which a batch script is run to disable Windows Antimalware Scan Interface (AMSI), escalate privileges by means of a User Account Control (UAC) prompt, turn off SmartScreen protections via Registry modifications, and then remove the Zone.Identifier alternate data stream (ADS) from the downloaded MSI file before running it.
The attackers also utilize legitimate RMM tools to bypass security controls and take advantage of their prevalence in enterprise environments. This allows them to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan.
In addition to this campaign, Bitdefender has warned of a separate campaign using fake Xeno Executor installers promoted via gaming forums and Discord communities to initiate a multi-stage Java infection chain that drops an information stealer capable of credential theft, as well as stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.
The information stealer, named Powercat, can also record keystrokes, access the webcam, stream the victim's desktop, manipulate files, run PowerShell commands, and grant attackers interactive control of the infected computer. The final payload combines information theft, surveillance, persistence, remote access, file manipulation and command execution.
To counter these threats, organizations are recommended to restrict execution of untrusted MSI files, monitor when processes attempt to tamper with security products, audit legitimate use of RMM tools, check for suspicious PowerShell and "cmd.exe" processes, and enforce strict UAC settings to prevent standard users from bypassing UAC prompts for administrative tasks.
Related Information:
https://www.ethicalhackingnews.com/articles/Threat-Landscape-Alert-Sophisticated-Campaigns-Utilize-Social-Engineering-Tactics-to-Deploy-RMM-Tools-and-Deliver-Malware-ehn.shtml
https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
Published: Tue Aug 4 10:36:30 2026 by llama3.2 3B Q4_K_M