# The Update That Isn't: How Attackers Are Hiding Backdoors Behind Adobe and Zoom


Your end users are one fake popup away from handing attackers persistent remote access to your network — and the tool doing the damage is probably already whitelisted by your security stack.


Securonix's threat research team has detailed an active multi-wave campaign they've dubbed SMOKE#SCREEN, and the mechanics are worth understanding closely. Attackers are running a social engineering operation built around believable, high-trust impersonation: fake Adobe software update prompts, spoofed Zoom installers, business document review notifications, and faux system maintenance utilities. The payload isn't ransomware or a novel zero-day. It's ConnectWise ScreenConnect — a legitimate, commercially sold remote monitoring and management tool that security tools are often explicitly configured to trust.


That's the whole game, and it's working.


---


## Why ScreenConnect and Why Now


ConnectWise ScreenConnect doesn't need an introduction to anyone who's worked IT or security for the past decade. It's ubiquitous in managed service provider environments, help desks, and enterprise IT departments. It's licensed software with a legitimate business purpose. It passes security scans because it's supposed to be there.


Attackers have understood this for years. The logic is brutal in its simplicity: if you can get a user to install a legitimate RMM agent, you have full remote access that looks exactly like what your IT team does every day. No custom malware. No shellcode. No obvious indicators of compromise hitting your SIEM. Just a support session that never ends.


SMOKE#SCREEN isn't the first campaign to weaponize ScreenConnect, and it won't be the last. What's notable here is the sophistication of the delivery mechanism. The lure selection — Adobe updates, Zoom installers, business document reviews — represents deliberate targeting of the mental model employees have developed around trusted software. Zoom's pandemic-era adoption made it a fixture in corporate environments. Adobe's ubiquity means an update prompt reads as routine. A "business document review" email lands differently than a generic phishing attempt; it implies the target is already known and expected.


Multi-wave campaigns also signal professional operation. This isn't spray-and-pray phishing. The layered approach — testing what gets through, adjusting the lure, retrying — is characteristic of groups running structured, persistent operations, not opportunistic one-shot attacks.


---


## The RMM Abuse Playbook


The use of commercial RMM tools as attack infrastructure has become so prevalent that CISA issued a specific advisory on the technique in January 2023, noting that multiple threat actor groups — including financially motivated cybercriminals — had exploited legitimate RMM software to maintain persistent access in targeted environments.


The mechanics of why this works are worth spelling out:


Allowlist blind spots. Enterprise environments routinely whitelist RMM tools because blocking them breaks legitimate IT operations. ScreenConnect, AnyDesk, TeamViewer, and similar tools operate in a gray zone where security products can't simply flag them as malicious without generating enormous false-positive noise.


Command-and-control without custom infrastructure. When an attacker operates through a legitimate RMM platform's cloud infrastructure, they don't need to stand up their own C2 servers. Traffic goes to ConnectWise's servers — the same servers your IT team uses. Network-level detection becomes dramatically harder.


Persistence by design. RMM tools are engineered to survive reboots, reconnect after network drops, and maintain sessions across long periods. Attackers get enterprise-grade reliability for their backdoor.


Operator familiarity. Once installed, ScreenConnect gives an attacker the same interface a help desk technician uses. File transfers, command execution, screen viewing — all through a polished GUI that doesn't require custom tooling expertise.


SMOKE#SCREEN is essentially packaging this playbook with a better delivery mechanism. The campaign's reliance on software update themes exploits a moment when users are mentally primed to click through: they've been trained that updating software is good security hygiene. Using that conditioning against them is an effective inversion.


---


## What Defenders Are Actually Up Against


The challenge here isn't technical — it's procedural and architectural.


Most organizations that would catch this attack aren't catching it because of better malware signatures. They're catching it because they've solved the inventory and policy problem: they know exactly which RMM tools are authorized, which hosts they should be running on, and they alert on any new RMM process appearing on endpoints that shouldn't have one.


That's the actual defense. Not blocking ScreenConnect — blocking unexpected ScreenConnect.


Concrete steps that matter here:


  • Inventory authorized RMM tools and restrict installation. Application control policies that require signed, pre-approved software are highly effective against this class of attack. Users should not be able to install RMM agents without administrative approval.
  • Alert on new RMM process execution. A workstation that hasn't had ScreenConnect before suddenly running it is an anomaly worth investigating immediately.
  • Scrutinize software update prompts that come through browser popups. Legitimate Adobe and Zoom updates don't arrive as browser-initiated download prompts. Training users to recognize this distinction has real value.
  • Check ScreenConnect relay domains. Attacker-deployed instances often use ScreenConnect's cloud relay but with attacker-controlled instance IDs. Some organizations are blocking the specific relay endpoints associated with known malicious deployments.
  • Network baseline. If ScreenConnect traffic appears on a host or subnet where it shouldn't exist, that's a detectable signal — but only if you know what your baseline looks like.

  • ---


    ## HackWire Analysis


    SMOKE#SCREEN deserves attention not because it's technically novel, but because it reflects where the threat landscape has settled in 2025: attackers don't need custom malware when legitimate commercial tooling does the job better and evades detection more reliably. This is the normalization of "living off the trusted land" — not just living off the land with OS binaries, but living off the entire ecosystem of commercially licensed enterprise software.


    ConnectWise specifically has had a difficult few years on the security front. CVE-2024-1709, the critical authentication bypass disclosed in February 2024, was exploited at mass scale within hours of publication — ransomware groups, state-sponsored actors, and opportunistic criminals all piling in simultaneously. The underlying lesson from that incident was that ScreenConnect's wide deployment footprint makes it a high-value target: compromise the tool, compromise every organization running it.


    SMOKE#SCREEN flips that logic. Instead of attacking ScreenConnect the product, attackers are using ScreenConnect the installation mechanism — getting victims to voluntarily install the same software that was weaponized in the 2024 vulnerability wave.


    What's missing from most coverage of this campaign is the downstream exposure question. When ScreenConnect gets installed on a corporate endpoint through social engineering, the attacker typically has access to everything that endpoint can reach. In environments where lateral movement controls are weak — flat networks, over-permissioned service accounts, cached domain credentials — a single successful install can become a full network compromise. The install event is the foothold; what happens next depends on the target's internal architecture.


    MSPs should treat this as a direct threat model. If attackers are specifically impersonating RMM update flows, they understand their targets often include IT and MSP staff — people with privileged access to many client environments simultaneously.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)