Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

The Hacker News · High sophistication
Last updated August 4, 2026

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT tooling. A separate campaign also uses fake “Xeno” Roblox cheat installers promoted on Discord/forums to deliver a powerful Java-based information stealer.

Key findings

  • Active, multi-wave campaign uses social-engineering themes (Adobe/Zoom updates, document reviews, system maintenance) to deploy ConnectWise ScreenConnect for persistent remote access.
  • Initial access is assessed as spear-phishing delivering an obfuscated VBScript dropper; other paths include business-themed lures and compressed-archive delivery.
  • Attackers abused trusted platforms (e.g., Dropbox shared links) and temporary Cloudflare tunnels to evade reputation monitoring.
  • Separate campaign uses fake “Xeno Executor” game-cheat installers promoted in forums/Discord to infect users with a Java-based stealer (Powercat) that steals credentials/cookies and enables remote control.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Legal, Operations, Executive assistants, IT/Helpdesk, Security operations (for RMM monitoring).
  • Affected industries: General enterprise / corporate users, Gaming communities / consumers.
  • Attack channels: email, website, discord.
  • Impersonated: Zoom (software update), Business contact / document sender, Xeno Executor / cheat-tool distributor.

Awareness takeaways

  • Treat “software update” emails and pages as suspicious, use the official app updater or vendor website, not links in messages.
  • Never run scripts or unusual file types to view a “document.” Escalate to IT/Security if a document requires running VBScript/BAT/MSI.
  • Watch for legitimate remote-access tools being installed unexpectedly; they can be abused to give criminals persistent control.
  • Block or closely monitor software downloads from forums/Discord for “cheats” and unofficial tools, these are common malware lures.

Red flags to watch for

  • Update delivered via a file-sharing link instead of official update mechanism
  • Unexpected HTML update page (e.g., “zoom-update.html”)
  • Installer results in remote-access tool installation rather than a normal Zoom update
  • A “document review” request that requires running a script (VBScript)
  • Unusual file types for documents (e.g., .vbs, .bat, .cmd, .msi)
  • Email pushes urgency to execute a file rather than use standard document formats
  • Software promoted via Discord/forums rather than official sources
  • Archive contains “plausible” files but requires running an executable to get a cheat
  • Tool requests actions inconsistent with a simple installer (multi-stage behavior)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Zoom Update Required, Please Install the Latest Version.” Looks routine, right? You click. A “zoom-update.html” page opens from a Dropbox link, downloads an installer… but instead of Zoom, it quietly installs ScreenConnect so someone can sit on your machine like IT. Same trick with “Document Review Needed” emails that tell you to run a .vbs script. Different lure, same endgame: a ScreenConnect agent sitting there, giving persistent remote access. If an email or chat tells you to update software or run a script, don’t click it, open the app or vendor website yourself, and if it still seems off, send it to IT.

Similar attacks

Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
ClickFix Lures Spread ChainScript RAT

ClickFix Lures Spread ChainScript RAT

Researchers describe real-world “ClickFix” social-engineering lures that trick people into installing malware by downloading fake apps (like Spotify/Zoom/Teams) or copying commands into Terminal. One campaign abused a compromised, verified HBO Max Reddit account to run malicious ads, while another…

September 21, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026