As cited
Copy frozen at (site build).
threat intel
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Researchers disclosed an active campaign using fake Adobe and Zoom update notifications to trick users into installing ConnectWise ScreenConnect, a remote monitoring and management tool. The multi-wave social engineering attack, codenamed SMOKE#SCREEN by Securonix, also employs lures around business document reviews and system maintenance utilities to establish persistent remote access.
Why it matters: Organizations relying on user vigilance against software update prompts face immediate risk of credential theft and system compromise; security teams should alert staff to verify update sources and block ScreenConnect installations where not authorized.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Researchers disclosed an active campaign using fake Adobe and Zoom update notifications to trick users into installing ConnectWise ScreenConnect, a remote monitoring and management tool. The multi-wave social engineering attack, codenamed SMOKE#SCREEN by Securonix, also employs lures around business document reviews and system maintenance utilities to establish persistent remote access.
Why it matters: Organizations relying on user vigilance against software update prompts face immediate risk of credential theft and system compromise; security teams should alert staff to verify update sources and block ScreenConnect installations where not authorized.
- Source published
- First seen by Cybersecurity Tracker