Researchers reported an active Smoke#Screen social-engineering campaign that tricks victims into installing the legitimate, ConnectWise-signed ScreenConnect remote monitoring and management tool, giving attackers persistent remote access while blending in with normal IT activity. The operation targets both Windows and macOS users and uses multiple lures, including fake Zoom and Adobe updates, document-review requests, and a SystemCheck maintenance tool. Securonix linked the activity to a live staging server at 207.174.0.143:8080, reconstructed five kill chains, and tied the campaign to three attacker-controlled ScreenConnect relay clusters.
The attackers rotated payloads between download sessions and used a mix of VBScript droppers, batch loaders, compiled .NET executables, phishing HTML pages, Dropbox links, Cloudflare Quick Tunnels, encrypted bundles, and a WsgiDAV staging server to frustrate hash-, signature-, and reputation-based detection. Researchers said the tradecraft evolved from obfuscated, sandbox-aware droppers to loaders that disabled Microsoft Defender and later to stealthier variants that delayed execution to evade Elastic correlation, underscoring that behavioral detection is more effective than relying on software trust or static indicators alone.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
Securonix reconstructed five distinct kill chains from collected samples and infrastructure mapping and assessed the activity as a capable, actively maintained, rapidly adapting threat operation. The published analysis recommended behavioral detections for unauthorized RMM installation, Defender tampering, raw-IP ScreenConnect connections, and suspicious parent-child process chains.
LevelBlue OpsCTI documented a large-scale phishing campaign distributing unauthorized ConnectWise ScreenConnect clients through fake update, meeting, invitation, and document portal lures. The analysis described platform-aware phishing pages, Telegram-based victim telemetry collection, and infrastructure reuse across thousands of phishing frameworks, and noted a significant increase in activity in July 2026.
During the investigation, Securonix observed the actor replace MemoryLoader.cs with loader.cs. The new version included the comment '// WAIT 3 MINUTES (Breaks Elastic correlation),' indicating a shift from aggressive Defender disabling toward delayed execution to evade EDR correlation.
Researchers found C# source code left in an open directory alongside compiled builds, including MemoryLoader.cs, which served as the template for compiled EXE loaders. The exposed code let Securonix observe feature additions between versions and determine that some differently named binaries were actually the same file.
Securonix found a macOS package named ZoomUpdateInstaller.pkg that connected to the same primary relay server as the Windows payloads. This showed the campaign targeted both macOS and Windows victims.
The campaign's final payloads were legitimate ConnectWise-signed ScreenConnect MSI installers delivered through methods including Dropbox and Cloudflare Quick Tunnels. Once installed, the agents beaconed to attacker-controlled relay servers and provided persistent remote access while blending in with normal administration activity.
Securonix observed the actor rotating payload hashes between individual download sessions, which reduced the usefulness of hash-based detection across investigative sampling periods. This behavior was part of the campaign's effort to evade signature-based defenses.
Researchers found three attacker-controlled ScreenConnect relay clusters at 207.174.0.143:8041, 142.202.191.225:8041 and :80, and blog.derrspecial-onlinedmin.live:8041. Independent RSA key pairs indicated deliberate operational compartmentalization, and one cluster used port 80 as a fallback to bypass outbound firewall restrictions.
Securonix began its investigation from a telemetry-submitted VBScript dropper named zoom-update.vbs and traced it to a live WsgiDAV staging server at 207.174.0.143:8080. The server exposed 15 payload files through an open directory listing.
Securonix tracked an active social-engineering campaign it named SMOKE#SCREEN that used Zoom update, business document review, system check, and Adobe update themes to trick users. The objective was to install legitimate ScreenConnect agents for persistent remote access on both Windows and macOS systems.
Securonix identified earlier VBScript samples in the campaign that downloaded remote C# source code from 207.189.11.170 and used crestmarkhq.com behind Cloudflare as part of delivery. These samples show an earlier stage of the actor's infrastructure and tooling before later loader changes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 75 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
levelblue.com
Open sourcetrojan-killer.net
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcedarkreading.com
Open sourcesecuronix.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.