preloader

· · digital-security devops malware rmm endpoint-security europe incident-response

A Fake Zoom Update Page Now Installs a Real, Digitally Signed Remote Access Tool on Your Network

Source: The Hacker News

The most effective malware right now often is not malware at all, at least not by the definition your antivirus checks against. It is a legitimate, digitally signed product, installed by someone who believed they were fixing a stale copy of software they use every day.

A convincing update page, a real remote access tool

Securonix’s threat research team has been tracking a multi-wave campaign it has named SMOKE#SCREEN, built around fraudulent update pages that closely replicate the branding, logos and version messaging of genuine Zoom and Adobe update prompts, alongside lures themed as business document reviews and system maintenance utilities. In every observed case, the final payload is ConnectWise ScreenConnect, a widely used, commercially licensed remote monitoring and management platform. Because ScreenConnect is signed, commonly present in enterprise environments, and used daily by legitimate IT teams, its installation does not reliably trigger the alerts a custom remote access trojan would. Once running, it connects out to attacker-controlled infrastructure, giving the operators hands-on-keyboard access without the victim noticing anything beyond an update dialog closing.

Not staying on Windows

Researchers have already found a fake macOS installer using the same lure structure, evidence that the campaign is actively maintained and being adapted to reach organisations running mixed device fleets rather than a single platform. That expansion matters for any business that assumed Mac users were a lower-priority target for this kind of social engineering.

Why “it’s just an update” keeps working

Attackers using signed RMM tools as their final payload is not new, but campaigns like SMOKE#SCREEN show why it remains effective: the tool itself will pass a software allowlist check, a code-signing verification, and often an EDR product’s default policy, because on paper it is exactly what it claims to be. The defence has to shift from “is this software malicious” to “did we authorise this specific installation, on this specific machine, right now.” For European organisations already tightening third-party and endpoint controls under NIS2, an unauthorised RMM tool showing up on an endpoint is precisely the kind of gap a risk assessment is meant to surface before an attacker finds it first.

If you want a review of which remote access and RMM tools are actually authorised to run across your endpoints, versus what is quietly installed, or help building detection for unsanctioned software regardless of whether it is digitally signed, contact Excello Digital. We help European businesses close the gap between assumed and actual endpoint control.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!