• Hackers use fake Adobe and Zoom updates to load malware onto vict

    From TechnologyDaily@1337:1/100 to All on Wed Aug 5 17:15:23 2026
    Hackers use fake Adobe and Zoom updates to load malware onto victim devices here's what to look out for

    Date:
    Wed, 05 Aug 2026 16:10:00 +0000

    Description:
    SMOKE#SCREEN is a dangerous campaign that evolves over time to avoid being spotted by defenders.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Securonix uncovers
    SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate remote monitoring and management (RMM) software.

    Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages,
    as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to
    convince the victims to run malicious files. Victims who dont see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and clients. However, it is also one of the more abused solutions in the criminal cyber-underworld, since it can often fly under the radar of security products. Latest Videos From TechRadar Watch full video here: Dangerous evolution After installation, attackers can remotely access compromised devices, potentially allowing them to steal data, install additional threats, or move deeper into an organizations network.

    At first glance, SMOKE#SCREEN looks like a fairly standard phishing - install legitimate RMM - remote access campaign. However, what makes it unique is how it evolved over time, Securonix explained. Earlier versions focused on hiding the malicious activity, while newer versions attempted to disable security protections and avoid detection by security software. The attackers also used trusted services such as Dropbox and Cloudflare to deliver their files,
    making the activity harder to block. You may like HP warns hackers are
    turning popular remote access tools into dangerous, stealthy backdoors
    Experts warn of 'highly sophisticated' weaponized JPEG campaign used to send out ScreenConnect malware Hackers abuse UltraVNC, Splashtop, and
    ScreenConnect to hijack business PCs

    Victims were observed on both Windows and macOS ecosystems, it was added.

    The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments, the researchers explained. Are you a pro? Subscribe to our newsletter Sign up to the
    TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.

    To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting.

    Via The Hacker News The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/hackers-use-fake-adobe-and-zoom-updates -to-load-malware-onto-victim-devices-heres-what-to-look-out-for


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)