The most effective malware right now often is not malware at all, at least not by the definition your antivirus checks against. It is a legitimate, digitally signed product, installed by someone who believed they were fixing a stale copy of software they use every day.
A convincing update page, a real remote access tool
Securonix’s threat research team has been tracking a multi-wave campaign it has named SMOKE#SCREEN, built around fraudulent update pages that closely replicate the branding, logos and version messaging of genuine Zoom and Adobe update prompts, alongside lures themed as business document reviews and system maintenance utilities. In every observed case, the final payload is ConnectWise ScreenConnect, a widely used, commercially licensed remote monitoring and management platform. Because ScreenConnect is signed, commonly present in enterprise environments, and used daily by legitimate IT teams, its installation does not reliably trigger the alerts a custom remote access trojan would. Once running, it connects out to attacker-controlled infrastructure, giving the operators hands-on-keyboard access without the victim noticing anything beyond an update dialog closing.
Not staying on Windows
Researchers have already found a fake macOS installer using the same lure structure, evidence that the campaign is actively maintained and being adapted to reach organisations running mixed device fleets rather than a single platform. That expansion matters for any business that assumed Mac users were a lower-priority target for this kind of social engineering.
Why “it’s just an update” keeps working
Attackers using signed RMM tools as their final payload is not new, but campaigns like SMOKE#SCREEN show why it remains effective: the tool itself will pass a software allowlist check, a code-signing verification, and often an EDR product’s default policy, because on paper it is exactly what it claims to be. The defence has to shift from “is this software malicious” to “did we authorise this specific installation, on this specific machine, right now.” For European organisations already tightening third-party and endpoint controls under NIS2, an unauthorised RMM tool showing up on an endpoint is precisely the kind of gap a risk assessment is meant to surface before an attacker finds it first.
If you want a review of which remote access and RMM tools are actually authorised to run across your endpoints, versus what is quietly installed, or help building detection for unsanctioned software regardless of whether it is digitally signed, contact Excello Digital. We help European businesses close the gap between assumed and actual endpoint control.
