Fake Adobe and Zoom update prompts are being used to silently install remote access tools on business computers.
If your employees download what looks like a routine software update, they could hand attackers persistent, undetected control over your systems.
Key takeaways
- Securonix Threat researchers codenamed this campaign SMOKE#SCREEN. It uses fake Adobe and Zoom update prompts, business document review notices, and system maintenance lures to trick users into running malicious installers.
- The payload is ConnectWise ScreenConnect, a legitimate RMM tool. Because security software recognizes it as a trusted application, standard antivirus tools may not flag the installation as a threat.
- Multi wave delivery lets attackers rotate lure themes until one succeeds, which makes it harder for employees to build a single mental pattern for spotting the attack.
- For SMBs, the core risk is persistence. Once ScreenConnect is installed, attackers can return at any time to move laterally, exfiltrate data, or stage ransomware without triggering obvious alarms.
Securonix Threat researchers have disclosed an active, multi wave campaign targeting businesses through fake software update prompts. Codenamed SMOKE#SCREEN, the campaign uses social engineering lures built around Adobe and Zoom branding, business document review requests, and system maintenance utilities. The objective is to deploy ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management (RMM) tool, as a backdoor for persistent remote access.
The word legitimate matters here. ScreenConnect is used by thousands of IT departments and managed service providers every day for remote support. That familiarity is exactly what makes this attack effective. Security tools trained to flag malware often pass ScreenConnect without scrutiny because, in most environments, it belongs there.
Fake Adobe and Zoom update prompts are among the most reliable social engineering lures in the attacker playbook. Employees expect periodic update notifications. They have been told for years to keep software current. When a pop up says a Zoom or Adobe product needs an update, clicking through feels like the responsible thing to do. SMOKE#SCREEN exploits that instilled habit directly.
The multi wave structure of this campaign deserves attention. Rather than committing to a single lure, attackers rotate themes. One wave might use fake Adobe update prompts. Another targets users with business document review notices. A third poses as a system maintenance utility. This rotation makes it harder to write a single detection rule or train employees around one specific scenario.
Once a user runs the malicious installer, ScreenConnect is deployed quietly in the background. From that point forward, the attacker holds a persistent foothold. Reconnecting at any time, observing activity, moving to other machines on the network, accessing files, or preparing a follow on attack such as ransomware are all within reach. The initial intrusion may go completely unnoticed for days or weeks.
For SMB owners, the practical implication is straightforward: your perimeter defenses may not catch this. Firewalls and antivirus tools that rely on signature based detection will often allow ScreenConnect to run because it is not inherently malicious. Catching this kind of attack requires behavioral monitoring. Your security stack needs to alert when a known RMM tool appears on a machine where IT never installed it.
IT managers should audit which machines currently have ScreenConnect or any other RMM tool installed and verify that each installation is authorized. Unauthorized RMM presence is a red flag regardless of how the tool arrived. If your team cannot account for an installation, treat it as a compromise until proven otherwise.
Employee awareness training needs to address update prompt skepticism specifically. Staff should know that legitimate software updates almost never require downloading a separate installer from a browser prompt. Adobe and Zoom both update through built in application mechanisms or through IT managed deployment tools, not through pop ups that send users to external download links.
Application allowlisting is one of the more effective technical controls against this class of attack. Restricting execution to pre approved applications means a malicious installer dropped by a fake update prompt will fail before it can run. This control takes effort to implement and maintain, but for higher risk environments the operational overhead is justified.
Multi factor authentication on all internal systems limits what attackers can do after gaining a foothold. Even with ScreenConnect installed and running, an attacker who tries to access your email platform, file server, or cloud applications will hit an additional barrier if MFA is enforced. It does not stop the initial compromise, but it narrows the blast radius considerably.
Network segmentation adds another layer of friction. On a flat network, lateral movement is straightforward once one machine is compromised. Separating finance systems, operational systems, and general workstations into distinct segments with controlled access between them forces an attacker entering through one endpoint to work significantly harder to reach your most sensitive data.
The broader pattern behind SMOKE#SCREEN is not new, but the execution is increasingly polished. Social engineering lures have become convincing enough that even technically aware users can be fooled under the right conditions, particularly when they are busy, distracted, or acting on autopilot. Security posture at the SMB level cannot treat user vigilance as the last line of defense.
Managed detection and response services that monitor for anomalous RMM activity are increasingly important for businesses without a dedicated internal security operations function. The goal is to catch ScreenConnect or similar tools appearing outside your normal IT workflow and escalate before the attacker has time to act on their access.
Visibility into what remote access tools are running across your endpoints is no longer optional. This campaign is a concrete reason to close that gap now. A quarterly endpoint audit is a reasonable starting point, but real time monitoring is the standard worth working toward.
TeckPath Perspective: SMOKE#SCREEN is a clear example of why SMBs need behavioral monitoring and RMM auditing built into their security program, not just antivirus that checks file signatures and considers the job done.
The most dangerous tools on your network are often the ones that look like they belong there.
Need help with Fake Adobe and Zoom Updates Are Installing Remote Access Tools on Business Machines?
TeckPath helps Calgary, Toronto, and Canadian businesses manage, secure, and modernize IT — with 24/7 support and SOC 2 Type II practices.