logo

ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates

ID: aaff0881-a3cd-5ea4-8070-01cd17712146

STIX ID: report--aaff0881-a3cd-5ea4-8070-01cd17712146

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-08-05

Date Updated: 2026-08-05

Author: Mayura Kathir

...
...

SMOKE#SCREEN is a multi-wave, cross-platform campaign that silently deploys signed ConnectWise ScreenConnect agents via phishing lures (Zoom, Adobe, business documents) and obfuscated droppers/loaders; attackers hide execution windows, erase forensic artifacts, and use attacker-controlled relay servers to provide guest-like remote access, while evolving tradecraft to evade EDR/AV and leveraging reputable services (Dropbox, Cloudflare) for payload delivery. Securonix mapped multiple relay clusters and staging hosts, observed Defender tampering and Defender-evading loaders, and recommends inventorying ScreenConnect instances, flagging unknown relays/IP connections, and monitoring for AMSI/Defender tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.