Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
BLUF
Attackers are weaponizing social engineering to deploy ScreenConnect for persistent network access.
NEWS
A new campaign dubbed Smoke#Screen utilizes varied social engineering lures and rotating malware payloads to compromise systems. The primary objective is establishing persistent remote access via the ScreenConnect RMM tool on targeted networks.
Why I Care
This matters because RMM tools provide attackers with legitimate-looking administrative access, making detection difficult and enabling deep network infiltration. Organizations relying on these tools for IT management face heightened risk of data exfiltration and ransomware deployment.
Next Steps
Security teams should audit all installed ScreenConnect instances immediately and verify legitimacy. Implement strict allowlisting for RMM software and monitor for unauthorized installation events within the next 7 days.
Source: Dark Reading ·
