CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3801

As cited

Copy frozen at (site build).

threat intel

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Researchers disclosed an active campaign using fake Adobe and Zoom update notifications to trick users into installing ConnectWise ScreenConnect, a remote monitoring and management tool. The multi-wave social engineering attack, codenamed SMOKE#SCREEN by Securonix, also employs lures around business document reviews and system maintenance utilities to establish persistent remote access.

Why it matters: Organizations relying on user vigilance against software update prompts face immediate risk of credential theft and system compromise; security teams should alert staff to verify update sources and block ScreenConnect installations where not authorized.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Researchers disclosed an active campaign using fake Adobe and Zoom update notifications to trick users into installing ConnectWise ScreenConnect, a remote monitoring and management tool. The multi-wave social engineering attack, codenamed SMOKE#SCREEN by Securonix, also employs lures around business document reviews and system maintenance utilities to establish persistent remote access.

Why it matters: Organizations relying on user vigilance against software update prompts face immediate risk of credential theft and system compromise; security teams should alert staff to verify update sources and block ScreenConnect installations where not authorized.

VendorsAdobeConnectWiseZoom
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary