Ethical Hacking News
The SMOKE#SCREEN campaign is a sophisticated threat actor that has been using various tactics to gain persistent remote access to compromised systems. This campaign relies on the use of fake Zoom updates to install ScreenConnect RMM software, often masquerading as legitimate IT activity. The attackers' sophistication and adaptability have made this campaign noteworthy, highlighting the importance of employee education and staying vigilant in the face of evolving threats.
The SMOKE#SCREEN campaign uses fake Zoom updates to install ScreenConnect RMM software on victim machines. The attackers employ a toolkit of various tools, including VBScript droppers and HTML phishing pages, to facilitate the installation of ScreenConnect. The threat actor uses rotating social engineering lures, fake Adobe software notices, and other tactics to trick victims into installing the malicious software. The attackers utilize Cloudflare's Quick Tunnel service to generate ephemeral tunnels and evade detection. The campaign has undergone significant evolution since its earliest samples, with adaptations in response to changes in threat detection strategies. The threat actor targets Elastic specifically, using anti-EDR timing and self-contained encrypted bundles to avoid detection. The final payload is a legitimate ConnectWise-signed ScreenConnect MSI, signed with a valid DigiCert certificate chain.
The cybersecurity landscape has witnessed the emergence of various sophisticated threats in recent times, and one such campaign that has garnered significant attention is the SMOKE#SCREEN campaign. This threat actor has been utilizing a range of tactics to gain persistent remote access to compromised systems, often masquerading as legitimate IT activity.
At its core, the SMOKE#SCREEN campaign relies on the use of fake Zoom updates to install ScreenConnect RMM (Remote Monitoring and Management) software on victim machines. Once installed, this software provides the attacker with persistent full remote access to the system. The attackers employ a toolkit of various tools, including VBScript droppers, batch file loaders, compiled .NET executables, and HTML phishing pages, all designed to facilitate the installation of ScreenConnect.
Interestingly, the attackers have also been using rotating social engineering lures, fake Adobe software notices, business document reviews, system maintenance utilities, and other tactics to trick victims into installing the malicious software. These tactics not only highlight the sophistication of the threat actor but also underscore the importance of employee education in preventing such attacks.
One notable aspect of the SMOKE#SCREEN campaign is its use of a staging server hosted on the IP address 207.174.0[.]143, which also runs the primary ScreenConnect relay on port 8041. This allows the attackers to maintain remote control over already-compromised hosts efficiently. Moreover, the attackers have been utilizing Cloudflare's Quick Tunnel service to generate ephemeral tunnels, further evading detection.
The campaign has undergone significant evolution since its earliest samples, with the attackers adapting their tactics in response to changes in threat detection strategies. For instance, an early phishing page delivered its payload via a Dropbox shared link, bypassing domain reputation filters in most corporate environments. The attackers have also rotated across multiple trusted hosting services to evade detection.
The SMOKE#SCREEN campaign is notable for its use of anti-EDR (Endpoint Detection and Response) timing and self-contained encrypted bundles, which allow the threat actor to avoid detection by security products. Furthermore, the actors are targeting Elastic specifically, with an explicit comment in the source code indicating a deliberate delay between MSI installation and service start.
The final payload in every attack path is a legitimate ConnectWise-signed ScreenConnect MSI, signed with a valid DigiCert certificate chain. This is particularly noteworthy, as many EDR products apply reduced scrutiny to binaries signed by recognized enterprise software vendors.
In conclusion, the SMOKE#SCREEN campaign represents a sophisticated threat actor that has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments. The attackers' use of tactics such as social engineering lures, fake updates, and rotating payloads highlights the importance of staying vigilant in the face of evolving threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-SMOKESCREEN-Campaign-A-Sophisticated-Threat-Actors-Pursuit-of-Remote-Control-Access-ehn.shtml
https://securityaffairs.com/196637/uncategorized/smokescreen-campaign-abuses-screenconnect-to-give-attackers-remote-control-access.html
Published: Wed Aug 5 01:33:49 2026 by llama3.2 3B Q4_K_M