SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access — Threadlinqs Intelligence
As of 2026-08-04, SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote Access is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 34 indicators of compromise.
Threat ID: TL-2026-1880 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
An active, multi-wave social engineering campaign dubbed SMOKE#SCREEN delivers fake Zoom, Adobe Flash, and document-review lures that silently install legitimate DigiCert-signed ConnectWise
Securonix Threat Research (Shikha Sangwan, Akshay Gaikwad, Aaron Beardslee) tracks SMOKE#SCREEN as an active, multi-wave campaign in which adversaries use rotating social-engineering lures themed around Zoom software updates, business document reviews, system maintenance utilities, and Adobe Flash Player updates to deploy silent ScreenConnect Remote Monitoring and Management (RMM) agent installs. The campaign is not tied to a specific CVE or CVSS score; it is a malware delivery and RMM-abuse operation that exploits the trust enterprises place in legitimate, code-signed remote-access tooling. A live WsgiDAV (Python WebDAV) staging server at 207.174.0.143:8080 exposed an open directory of 15 payload files during investigation, and the same IP operated a ScreenConnect relay on port 8041 (dual-purpose delivery plus command and control). Beaconing was observed against three compartmentalized relay clusters, each with an independent RSA key pair: a primary cluster at 207.174.0.143:8041, a secondary cluster at 142.202.191.225:8041/80 (with a port 80 fallback to bypass restrictive firewalls), and a tertiary cluster at the domain blog.derrspecial-onlinedmin.live:8041, which is deliberately designed to blend in as an administrative portal. Early payload infra also included a former C# hosting node at 207.189.11.170 and the Cloudflare-proxied domain crestmarkhq.com.
Five distinct kill chains were reconstructed, each evolving in tradecraft. Kill Chain 1 uses an XOR-encrypted VBScript dropper (zoom-update.vbs) that runs environment checks (aborting if memory is below 2GB or if analysis tools such as wireshark, procmon, vboxservice, vmtoolsd, xenservice, or fiddler are present), walks a seven-state While/Select-Case state machine with junk arithmetic, decrypts a hex-encoded XOR payload (key gc1HXjFtHBbC659t), spawns hidden PowerShell, downloads working_payload.cs, and compiles C# in-memory via Add-Type. Kill Chain 2 uses a plain 23-line VBScript (RSKAdvGrpSupportingdocuments.vbs) impersonating an RSK Advisory Group business document, creating processes exclusively via the WMI Win32_Process class with ShowWindow=0 to avoid standard WScript.Shell detection. Kill Chain 3 is a batch/gzip loader (SystemCheck) that performs a reflection-based AMSI bypass, UAC auto-elevation, SmartScreen dismantlement via registry changes plus Explorer restart, and Defender exclusions for the entire %TEMP% directory and the MSI path, before silently installing the payload. Kill Chain 4 is a compiled .NET loader (MemoryLoader.cs, shipped as AdobeReader_Update.exe / NYbiLtvO.exe) that hides its console via P/Invoke and runs a nine-step Defender-destruction sequence through hidden PowerShell, then downloads the MSI via a Cloudflare Quick Tunnel (subscription-magnetic-recommended-meat.trycloudflare.com) using a Mozilla/5.0 User-Agent. Kill Chain 5 is a successor .NET loader (loader.cs, a roughly 50MB self-contained encrypted bundle shipped as zFbJVuiX.exe / Zoomupdateinstaller.exe) that drops the aggressive Defender destruction in favor of an avoidance strategy, including an explicit 180-second delay commented as 'WAIT 3 MINUTES (Breaks Elastic correlation)'.
The final payload in every path is a legitimate ConnectWise ScreenConnect MSI signed with a valid DigiCert Authenticode certificate issued to Connectwise, LLC — a living-off-the-land technique that evades EDRs applying reduced scrutiny to recognized vendor code signing. The MSIs beacon to the attacker-controlled relays (e.g., with e=Access&y=Guest parameters) for persistent remote desktop access. Cross-platform targeting is deliberate: macOS .pkg variants (ZoomUpdateInstaller.pkg, Zoomupdateinstaller.pkg) connect to the same primary relay as the Windows MSI payloads. The campaign also demonstrates active hash rotation (the original 15 staging files were rotated to 9 new files during investigation), making signature-based detection ineffective. No named threat group has been attributed; the actor is described as
Target sectors: all sectors
Target regions: Global
Detections & IOCs
As of 2026-08-10, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 34 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
11 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566.002, T1204.002, T1059.005, T1059.001, T1059.003, T1047, T1218.007, T1543.003, T1027, T1027.009