LIVEยท

Global News & Market Intelligence ยท Verified Official Dispatches

Editions:
LIVEMARKETS:
S&P 500 5,640.20 (+0.45% โ–ฒ)|NASDAQ 17,855.10 (+0.62% โ–ฒ)|BRENT CRUDE $82.40 (-0.85% โ–ผ)|BITCOIN $64,250.00 (+1.90% โ–ฒ)
S&P 500 5,640.20 (+0.45% โ–ฒ)|NASDAQ 17,855.10 (+0.62% โ–ฒ)|BRENT CRUDE $82.40 (-0.85% โ–ผ)|BITCOIN $64,250.00 (+1.90% โ–ฒ)
Breaking
Cybersecurityยท ๐ŸŒ Global

SMOKE#SCREEN Campaign Exploits ScreenConnect for Remote Access

According to Security Affairs, the SMOKE#SCREEN campaign is deploying fake software updates to install ConnectWise ScreenConnect and gain persistent remote access.

By Skyline Wire Newsroom ยท Published Source: Security Affairs ยท Verified Reporting

Key Story Metrics & Context

Industry Sector:Technology, Enterprise IT
Companies Impacted:ConnectWise, Zoom, Adobe
Geographic Scale:Global
Reporting Status:โœ“ Multi-Source Verified
SMOKE#SCREEN Campaign Exploits ScreenConnect for Remote Access

Executive Brief & Verified Analysis

โœ“ OFFICIAL SOURCES REVIEWED

Executive Summary

According to Security Affairs, the SMOKE#SCREEN campaign is deploying fake software updates to install ConnectWise ScreenConnect and gain persistent remote access.

Why This Matters

Key strategic implication: The campaign uses a staging server at 207.174.0.143:8080 to host 15 malicious payload files.

Market Impact

Verified for ConnectWise, Zoom, Adobe. Primary market adjustment vector.

Source Verification

Cross-referenced across regulatory dispatches, official press releases, and verified wire filings.

Strategic Implications

  • โœ“The campaign uses a staging server at 207.174.0.143:8080 to host 15 malicious payload files.
  • โœ“ScreenConnect is utilized as a legitimate RMM tool to grant attackers persistent access.
  • โœ“Early campaign iterations aborted if the target machine had less than 2 GB of RAM.
  • โœ“The attackers use an aggressive strategy involving disabling the WinDefend service and modifying registry keys.

According to Security Affairs, a sophisticated cyber operation identified as SMOKE#SCREEN is currently utilizing deceptive software lures to deploy the ConnectWise ScreenConnect remote monitoring and management (RMM) tool on target machines. By mimicking legitimate updates from software providers like Zoom and Adobe, attackers establish persistent, unauthorized access that closely resembles routine IT administrative activity.

Securonix Threat Research, which has been monitoring the campaign, reports that the attackers utilize a variety of delivery mechanisms including VBScript droppers, batch files, and .NET executables. A central staging server located at 207.174.0.143:8080 was discovered, containing 15 payload files in an openly browsable directory. This same infrastructure hosts a ScreenConnect relay on port 8041.

Infrastructure and Payload Data

AttributeSpecification
Staging Server IP207.174.0.143
Staging Port8080
Relay Server Port8041
Payload Files Discovered15
Minimum RAM Check2 GB

The campaign has demonstrated a marked evolution in tactics. Early iterations employed complex techniques like XOR encryption and environment checks to evade analysis, specifically aborting if the host machine contained less than 2 GB of RAM or detection tools like Wireshark and Process Monitor. Newer samples have adopted more aggressive methods, including disabling the Windows Defender (WinDefend) service, modifying registry keys to bypass SmartScreen, and applying memory patching to disable the Antimalware Scan Interface (AMSI).

Why It Matters

The SMOKE#SCREEN campaign highlights the danger of "living-off-the-land" techniques, where attackers abuse legitimate remote administration software to mask malicious presence. By integrating trusted tools into the attack chain, threat actors successfully lower the visibility of their persistent access. For enterprise environments, this underscores that relying on traditional signature-based detection is insufficient. Security teams must shift toward behavioral monitoring that can distinguish between authorized IT management traffic and unauthorized persistent beaconing, even when that traffic originates from enterprise-grade software such as ScreenConnect.

Expected Next Steps

  • 1Monitor enterprise networks for unauthorized ScreenConnect agents.
  • 2Implement strict controls on the installation of RMM software.
  • 3Verify the integrity of software update sources used within the organization.
  • 4Block traffic associated with the identified IP address 207.174.0.143.

Frequently Asked Questions

It is a multi-wave cyber campaign that uses social engineering and fake software updates to install the legitimate ScreenConnect tool for unauthorized remote access.

Attackers use VBScript droppers, batch files, and .NET executables, often hosted on a staging server at 207.174.0.143.

The attackers frequently change file payloads and use techniques such as disabling Windows Defender and memory patching to bypass security controls.

Source Transparency & Verified Dispatches

โœ“ Verified Primary Data
โœ“
Securonix๐Ÿ›๏ธ Government / Regulatory
Source โ†—
โœ“
Security Affairs๐Ÿ›๏ธ Government / Regulatory
Source โ†—

Reader Discussion & Insights

Leave a Comment

Loading discussion thread...

Get Breaking Global Intel in Your Inbox

Subscribe to the Skyline Wire AI Daily Briefing. Direct insights across Aviation, Tech, EVs, and Markets.

Original announcement link: Security Affairs

cybersecurityscreenconnectmalwarephishingremote-access
smoke#screen campaignscreenconnect malwaresecuronix threat researchremote access trojanfake zoom updatecybersecurity threat analysis207.174.0.143connectwise screenconnect