# The Help Desk That Wasn't: How Smoke#Screen Turned IT's Own Tools Against It
There's a particular cruelty to the Smoke#Screen campaign. It doesn't break through your defenses. It knocks on the front door, convinces someone to open it, and then moves in with the tools your IT team uses every day.
Researchers tracking Smoke#Screen have documented a multi-stage intrusion chain that puts ScreenConnect — ConnectWise's legitimate remote management platform — at the center of a persistent access operation. The attackers aren't exploiting a zero-day. They're exploiting the fact that ScreenConnect is already trusted by every endpoint it touches.
## The Playbook in Plain English
The campaign opens with social engineering, and that's where the sophistication actually lives. Smoke#Screen doesn't rely on a single pretext. Lures rotate — IT helpdesk impersonation, fake HR policy documents, software update notices — whatever fits the target's context. The delivery infrastructure shifts too, cycling through different payload mechanisms to stay ahead of signature-based detection.
The goal in every case is the same: get ScreenConnect installed and connected back to attacker-controlled infrastructure. Once that happens, the threat actor has what any legitimate MSP technician would have — full keyboard, full screen, full control. They can move files, run commands, enumerate the network, deploy additional tooling. And because ScreenConnect traffic looks like ScreenConnect traffic, it blends.
This is the RMM abuse playbook in its most refined form, and it's been a long time coming.
## Why ScreenConnect, Specifically
Remote monitoring and management tools have been threat actor favorites for years, but ScreenConnect occupies a particular position in that landscape. It's ubiquitous in managed service provider environments, deeply trusted by security controls, and — critically — it operates over outbound connections that most firewalls pass without complaint.
The tool had a bruising 2024. CVE-2024-1709, a critical authentication bypass in the on-premises version, was exploited within 24 hours of publication and became one of the year's most actively abused vulnerabilities. Ransomware operators, initial access brokers, and nation-state groups all piled in. ConnectWise patched it, organizations scrambled to update, and the industry moved on.
Smoke#Screen represents a different threat model — not a software vulnerability, but a deployment-by-deception approach. No unpatched server required. The attacker gets a victim to install a legitimate, fully licensed ScreenConnect client, pointed at infrastructure the attacker controls. Every subsequent action is entirely legitimate behavior by design.
## The Social Engineering Layer Is the Hard Part
What separates a mediocre phishing campaign from an effective one isn't the malware — it's the pretext. Smoke#Screen's rotating lures suggest a threat actor who has done their homework on target environments or, more likely, maintains a library of templates tuned for different industries and job functions.
IT helpdesk impersonation is particularly effective because it exploits the exact scenario where installing remote access software is the expected outcome. A message from "IT support" asking you to install a remote access tool to fix a problem is, in normal circumstances, completely normal. The attacker is weaponizing institutional procedure.
The payload rotation matters too. Static payloads get detected. Rotating delivery mechanisms — different file types, different staging techniques, different download paths — forces defenders to catch the behavior rather than the signature. That's a harder problem.
## What Defenders Actually Need to Do
The defensive answer here isn't blocking ScreenConnect. Organizations that rely on MSPs or internal IT teams need remote management tools. Blocking them creates a different category of operational problem.
The controls that actually matter:
RMM inventory and allowlisting. Know which RMM tools are authorized in your environment and which relay servers they should be connecting to. An unexpected ScreenConnect session connecting to an unfamiliar domain is an anomaly worth chasing. Most organizations have no idea what relay endpoints their RMM traffic reaches.
Application control with attention to unsigned or newly-appeared installers. ScreenConnect clients are signed, but the deployment context matters. An installer that appeared in a user's downloads folder after clicking a link in email is a different risk profile than one deployed by your MDM.
Email gateway scrutiny on lure artifacts. Helpdesk impersonation, fake HR documents, software update notices — these all have detectable characteristics. Thread-jacking, mismatched sender domains, unusual attachment types, links to fresh domains. None of these controls are new, but they require tuning.
User awareness that specifically addresses IT impersonation. Most security awareness programs cover phishing generically. Few specifically train users on the scenario where someone impersonating IT asks them to install remote access software. That's the exact scenario Smoke#Screen exploits, and it's worth dedicated training.
---
## HackWire Analysis
The timing of Smoke#Screen's exposure matters. The MSP and RMM space is under sustained pressure from attackers precisely because it represents a privileged access pathway to downstream customers. Compromise one MSP's tooling, and you potentially have access to dozens or hundreds of client environments — all through infrastructure those clients already trust.
What's getting insufficient attention in coverage of this campaign is the compounding risk for small and mid-sized businesses who depend entirely on MSPs for IT operations. Those organizations typically have no visibility into what RMM traffic looks like on their networks, no ability to independently verify that a ScreenConnect session was initiated by their actual IT provider, and no security team to notice when something looks off. They've outsourced trust entirely to the MSP relationship — and Smoke#Screen exploits exactly that gap by impersonating the trusted party.
This also fits a pattern that's been building since CISA and the FBI issued their joint advisory on RMM abuse in January 2023. That advisory named AnyDesk and ScreenConnect specifically. The industry acknowledged the problem, patched where there were vulnerabilities to patch, and largely moved on. Smoke#Screen is evidence that the underlying threat model — attackers using legitimate tooling to blend into normal operations — didn't move on with it.
The realistic answer for defenders isn't tool replacement. It's visibility. You can't stop what you can't see, and most organizations have effectively zero visibility into the behavioral envelope of their remote management traffic. Building that baseline — what endpoints connect to what relay servers, with what frequency, initiated by what process trees — is the necessary foundation. Without it, detection is luck.
For MSPs directly: your clients trust you at the network layer. An attacker who convincingly impersonates your brand, even briefly, inherits that trust. That's worth taking seriously in how you communicate with clients and how you verify session initiation.
— HackWire Editorial
---
## Related Coverage