logo

Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook

ID: 0e66c0ff-704a-5645-9996-1434967566d4

STIX ID: report--0e66c0ff-704a-5645-9996-1434967566d4

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Elizabeth Montalbano

ADMIRALTY:B6
...
...

**Smoke#Screen** is an active, sophisticated social-engineering campaign that uses lures (purported Zoom/Adobe updates, document-review requests, and a "SystemCheck" maintenance prompt) to silently install legitimate ConnectWise/ScreenConnect RMM agents, giving attackers persistent, signed remote access on Windows and macOS; the actor rotates payloads per download session, uses Cloudflare tunnels, Dropbox, and signed binaries to evade detection, and Securonix mapped multiple kill chains, three relay servers, and 15 unique payloads. Defenses recommended include behavioral EDR detections for unauthorized RMM installs and tampering, UAC hardening, detection of ScreenConnect connections to raw IPs, and rules for anomalous parent-child process relationships.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.