Fake Adobe and Zoom Update Prompts Slip Remote-Control Software Onto Victim PCs

Securonix researchers say the SMOKE#SCREEN campaign is tricking staff into installing ConnectWise ScreenConnect, handing attackers a quiet way back in.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal shot of a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface, with faint
Share

Key points

  • Securonix has named an active campaign SMOKE#SCREEN that uses fake Adobe and Zoom update prompts to install remote-access software on victim machines.
  • The tool being installed is ConnectWise ScreenConnect, a legitimate Remote Monitoring and Management product that attackers are abusing to keep long-term access.
  • Lures also include fake business document reviews and system maintenance utilities, aimed at office workers who click without thinking.
  • Because ScreenConnect is real IT software, many antivirus tools do not flag it, giving the intruders quiet, persistent control.
  • Multi-factor authentication would not have stopped this one on its own: the trick happens after login, on the endpoint itself.

A new wave of attacks is using fake software update pop-ups, the kind that look like a routine Adobe or Zoom prompt, to sneak remote-control software onto people's computers. Once installed, the attackers can watch the screen, move files, and come back whenever they like.

Securonix's threat research team is calling the campaign SMOKE#SCREEN, and says it is running in multiple waves with different lures. The Hacker News first flagged the write-up.

What is actually being installed?

The payload is ConnectWise ScreenConnect, a real product that IT departments use every day to fix computers remotely. In the wrong hands it becomes a spying tool. Because it is signed, legitimate software, most antivirus products leave it alone.

That is the whole trick. The attackers do not need a fancy zero-day, meaning a secret software flaw the maker does not know about. They just need one employee to double-click an installer.

How are people being tricked into running it?

By pop-ups and emails that look like ordinary work interruptions. Securonix has seen at least four lure themes so far.

Lure theme What the victim sees
Adobe update A prompt claiming Adobe Reader or Acrobat needs a critical update
Zoom update A fake Zoom client update, often before a meeting
Document review An email asking them to open and review a business file
System maintenance A utility offering to "clean up" or repair the PC

Each lure ends the same way. The user runs an installer, ScreenConnect is quietly dropped onto the machine, and it phones home to a server the attackers control.

Why does this matter for ordinary staff?

Because the fake prompts look almost identical to the real ones. Adobe and Zoom both push genuine updates constantly, so a pop-up asking you to install one does not feel suspicious. That is exactly what the campaign is banking on.

Once the attackers have ScreenConnect running under your user account, they inherit whatever you can reach: email, shared drives, saved passwords in the browser, internal apps you are already signed into. This is where the identity side gets ugly. Even if your company uses single sign-on, meaning one login that opens many work apps, the attacker is already sitting inside your live session and does not need to log in again.

Would multi-factor authentication, the second step where you approve a login on your phone, have helped here? Honestly, no. The compromise happens on the endpoint after you are authenticated. MFA protects the front door. This attack walks in behind you.

What should people and companies do now?

Treat unsolicited update prompts with suspicion, especially ones that appear from a web page or an email attachment rather than from the app itself. Real Adobe and Zoom updates come from inside the running program, not from a browser download.

IT teams should check whether ScreenConnect is installed on machines that have no business running it. Securonix's write-up lists the domains and file hashes to hunt for. Blocking unauthorised RMM tools at the network edge is one of the cleanest wins available right now.

And if you clicked something odd this week? Tell your IT team today, not next Monday.

© 2026 Threat Vectr