SMOKE#SCREEN Campaign Leverages ConnectWise ScreenConnect to Grant Attackers Persistent Remote Control
What Happened — A new multi‑wave social‑engineering campaign dubbed SMOKE#SCREEN distributes fake Zoom and Adobe updates that silently install the legitimate remote‑monitoring tool ConnectWise ScreenConnect on victim machines. Once installed, the tool provides attackers with persistent, full‑remote access that appears indistinguishable from authorized IT activity.
Why It Matters for Compliance & Audit Readiness
- The attack exploits weak access‑control safeguards around privileged remote‑administration tools – a core SOC 2 CC6.1 (Logical Access) control that must be documented and continuously monitored.
- Persistent, “legitimate‑looking” agents bypass traditional endpoint alerts, highlighting the need for continuous evidence collection (e.g., agent inventory, usage logs) to prove that only approved users and processes can initiate remote sessions.
- The campaign’s reliance on social‑engineering underscores the importance of Security Awareness Training and policy enforcement, both required for SOC 2 CC6.2 (Security Awareness).
Who Is Affected — Enterprises that deploy remote‑monitoring/management (RMM) solutions across any industry; especially SaaS providers, MSPs, and internal IT teams that rely on ScreenConnect or similar tools.
Recommended Actions
- Inventory all RMM agents (ScreenConnect, TeamViewer, etc.) and reconcile against an approved‑use list.
- Enforce MFA and least‑privilege for any remote‑access accounts; log every session and retain logs for audit.
- Deploy continuous monitoring to detect newly‑installed agents or changes to Windows Defender exclusions and service states.
- Refresh security‑awareness training to cover fake‑update lures and the visual similarity of malicious remote sessions.
Source: Security Affairs
Technical Notes
- Attack vector: phishing‑based fake software updates (Zoom, Adobe) delivering VBScript, batch, and .NET payloads.
- Payloads disable AMSI, add Defender exclusions, stop WinDefend, and modify SmartScreen/registry to evade detection.
- Staging server: 207.174.0.143:8080 (WsgiDAV) with openly browsable directory of 15 payload files; relay on port 8041.