hacker-news · Crawled Aug 4, 2026

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

10 IoCs 1 Malware
Read original article ↗

AI Summary

An active multi-wave campaign dubbed SMOKE#SCREEN by Securonix uses fake Adobe and Zoom update lures, along with business document themes, to deliver Remote Monitoring and Management (RMM) tools like ConnectWise ScreenConnect. The attack begins with spear-phishing emails containing obfuscated VBScript droppers that perform anti-analysis checks before deploying payloads. These payloads ultimately install ScreenConnect, providing attackers with persistent remote access through attacker-controlled relay servers. A separate but related campaign distributes the Powercat Java-based information stealer via fake Xeno Roblox cheat installers, enabling credential theft, surveillance, and remote control.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 10 extracted

Type Value Detail
IP 207[.]174[.]0[.]143 Details →
IP 207[.]189[.]11[.]170 Details →
Domain solthere[.]net Details →
Filename zoom-update.html Details →
Filename xeno.exe Details →
Filename decompiler.exe Details →
Filename XenoIcon.jpg Details →
GitHub Repo subscription-magnetic-recommended-meat.trycloudflare.com Details →
MD5 not specified Details →
SHA-256 not specified Details →

MITRE ATT&CK TTPs 13 techniques