New 'Smoke#Screen' Campaign Hijacks Remote Access Tools to Infiltrate Networks
Security researchers have uncovered an active attack campaign, dubbed Smoke#Screen, that relies on a mix of social engineering tactics and constantly changing malicious payloads to trick victims into installing ScreenConnect, a legitimate remote monitoring and management (RMM) tool. Once installed, this software gives attackers ongoing remote access to the compromised system, allowing them to maintain a foothold in the network long after the initial breach.
What makes this campaign particularly concerning is its use of RMM software rather than traditional malware. Because tools like ScreenConnect are widely used by IT teams for legitimate purposes, their presence on a network may not immediately raise red flags with security software or staff, making the intrusion harder to detect. Attackers are rotating their lures and payloads, suggesting an adaptive approach designed to evade detection and improve success rates against a range of targets.
For small and medium businesses, this campaign is a reminder that not all threats come in the form of obviously malicious files. Legitimate-looking software, delivered through convincing social engineering, can be just as dangerous as traditional malware if it grants attackers persistent access to your systems.