Threat Intelligence

Beware Fake Adobe and Zoom Update Pop-Ups Hiding Remote Access Malware

The Hacker News · 4 Aug 2026
Key Takeaway Only download software updates directly from official vendor websites or built-in update mechanisms, never from pop-ups, email links, or unexpected prompts.

Security researchers have uncovered an active campaign, dubbed SMOKE#SCREEN, that tricks users into installing legitimate remote monitoring and management (RMM) tools for malicious purposes. The attackers disguise their lures as routine software updates for popular programs like Adobe and Zoom, fake business document reviews, and system maintenance utilities.

Once a victim clicks through these fake prompts, the campaign quietly installs ConnectWise ScreenConnect, a legitimate remote access tool that is widely used by IT support teams. Because ScreenConnect is trusted software rather than obvious malware, it can slip past many security tools undetected, giving attackers persistent, hands-on access to the compromised system without raising immediate alarms.

This approach highlights a growing trend where cybercriminals abuse legitimate IT tools instead of building custom malware, making detection more difficult for businesses relying on traditional antivirus protections. For small and medium businesses without dedicated IT security staff, a convincing fake update notification could easily lead to a full system compromise, opening the door to data theft, ransomware, or further network intrusion.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.