Fake Zoom Updates Install ScreenConnect Backdoor

Security Affairs · High sophistication
Last updated August 5, 2026

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT activity. The campaign rotates lures and hosting methods (e.g., Dropbox and Cloudflare tunnels) and adapts to security tools to avoid detection.

Key findings

  • Attackers use rotating lures (fake Zoom updates, Adobe notices, document reviews, system maintenance utilities) to get users to run files that install ScreenConnect for persistent remote access.
  • A polished fake Zoom update page auto-triggers a download after two seconds and tells the user to run an MSI to complete the update.
  • The campaign uses trusted platforms (e.g., Dropbox shared links) and Cloudflare tunnels to reduce suspicion and bypass reputation-based filtering.
  • Observed adaptation includes disabling defenses in earlier samples and later shifting to stealth (e.g., delaying execution to evade EDR correlation windows).
  • Final payload is a legitimate ConnectWise-signed ScreenConnect MSI, which may receive less scrutiny from some security products.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT Helpdesk, IT Operations, Security Operations (SOC).
  • Affected industries: Multiple industries (not specified).
  • Attack channels: website, email.
  • Impersonated: Zoom, Internal business contact or software vendor notice.

Awareness takeaways

  • Treat unexpected “software update” prompts (especially ones that download installers) as suspicious and verify through IT or the official vendor site.
  • Be cautious when links or downloads are hosted on trusted third-party services (e.g., file-sharing platforms); attackers use them to appear safe.
  • Remote access tools can be abused; employees should report any unexpected remote-control prompts or “IT-like” behavior on their device immediately.
  • Security teams should watch for ScreenConnect/RMM connections to raw IP addresses rather than normal vendor domains, and for suspicious MSI installs from temp locations.

Red flags to watch for

  • Update delivered via a web page that auto-downloads an installer after a short timer
  • Pressure/urgency language about security or connections failing
  • Unexpected request to run an MSI outside the normal corporate software update process
  • “Update” file hosted on a consumer file-sharing service instead of the vendor/corporate portal
  • Unexpected software update prompt outside standard IT channels
  • Installer/source does not match official vendor domains
  • Unsolicited request to open or run a file to view a document/notice
  • File type or execution required for a “document review” or “software notice”
  • Mismatch between the message’s claim and the organization’s normal workflow (e.g., software updates not managed by IT)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a Zoom call, it glitches, and a page pops up: “Zoom can’t make a secure connection, urgent update required.” Two seconds later, a file auto-downloads, ZoomUpdate.msi, and the page tells you, “Run this MSI to complete the update.” That’s SMOKE#SCREEN installing ScreenConnect for full remote control. Sometimes the “update” even comes from a Dropbox shared link that looks totally normal. But running it silently drops a legitimate, ConnectWise-signed ScreenConnect agent that looks just like real IT remote access. Aha moment: real Zoom never auto-downloads an MSI from random pages or Dropbox. If any “Zoom update” downloads an installer in your browser, stop and report it to IT immediately, don’t run it.

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake DocuSign Flow Tricks Users Into RMM Installs

Fake DocuSign Flow Tricks Users Into RMM Installs

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep…

July 20, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The campaign abused legitimate software and cloud services to load a malicious DLL, disable security tools, and establish remote access with…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Phishing Lab Used WebDAV to Push Fake “PDF” Malware

Investigators found an exposed WebDAV server being used as a “malware delivery lab” with over 1,000 files for testing lures, filenames, and execution tricks. One active campaign impersonated Mexico’s CURP ID lookup site and delivered malware by opening a remote WebDAV folder via a Windows…

July 20, 2026
Fake Bank of America Email Pushes Hidden ScreenConnect

Fake Bank of America Email Pushes Hidden ScreenConnect

Attackers are impersonating Bank of America in mass phishing emails to pressure people into clicking a link “to avoid account restrictions.” Mac users are led to a fake login page that steals credentials and personal/financial data, while Windows users are tricked into installing a ScreenConnect…

August 5, 2026