Fake Zoom Updates Install ScreenConnect Backdoor

Security Affairs · High sophistication
Last updated August 5, 2026

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT activity. The campaign rotates lures and hosting methods (e.g., Dropbox and Cloudflare tunnels) and adapts to security tools to avoid detection.

Key findings

  • Attackers use rotating lures (fake Zoom updates, Adobe notices, document reviews, system maintenance utilities) to get users to run files that install ScreenConnect for persistent remote access.
  • A polished fake Zoom update page auto-triggers a download after two seconds and tells the user to run an MSI to complete the update.
  • The campaign uses trusted platforms (e.g., Dropbox shared links) and Cloudflare tunnels to reduce suspicion and bypass reputation-based filtering.
  • Observed adaptation includes disabling defenses in earlier samples and later shifting to stealth (e.g., delaying execution to evade EDR correlation windows).
  • Final payload is a legitimate ConnectWise-signed ScreenConnect MSI, which may receive less scrutiny from some security products.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, HR, IT Helpdesk, IT Operations, Security Operations (SOC).
  • Affected industries: Multiple industries (not specified).
  • Attack channels: website, email.
  • Impersonated: Zoom, Internal business contact or software vendor notice.

Awareness takeaways

  • Treat unexpected “software update” prompts (especially ones that download installers) as suspicious and verify through IT or the official vendor site.
  • Be cautious when links or downloads are hosted on trusted third-party services (e.g., file-sharing platforms); attackers use them to appear safe.
  • Remote access tools can be abused; employees should report any unexpected remote-control prompts or “IT-like” behavior on their device immediately.
  • Security teams should watch for ScreenConnect/RMM connections to raw IP addresses rather than normal vendor domains, and for suspicious MSI installs from temp locations.

Red flags to watch for

  • Update delivered via a web page that auto-downloads an installer after a short timer
  • Pressure/urgency language about security or connections failing
  • Unexpected request to run an MSI outside the normal corporate software update process
  • “Update” file hosted on a consumer file-sharing service instead of the vendor/corporate portal
  • Unexpected software update prompt outside standard IT channels
  • Installer/source does not match official vendor domains
  • Unsolicited request to open or run a file to view a document/notice
  • File type or execution required for a “document review” or “software notice”
  • Mismatch between the message’s claim and the organization’s normal workflow (e.g., software updates not managed by IT)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re in a Zoom call, it glitches, and a page pops up: “Zoom can’t make a secure connection, urgent update required.” Two seconds later, a file auto-downloads, ZoomUpdate.msi, and the page tells you, “Run this MSI to complete the update.” That’s SMOKE#SCREEN installing ScreenConnect for full remote control. Sometimes the “update” even comes from a Dropbox shared link that looks totally normal. But running it silently drops a legitimate, ConnectWise-signed ScreenConnect agent that looks just like real IT remote access. Aha moment: real Zoom never auto-downloads an MSI from random pages or Dropbox. If any “Zoom update” downloads an installer in your browser, stop and report it to IT immediately, don’t run it.

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake DocuSign Flow Tricks Users Into RMM Installs

Fake DocuSign Flow Tricks Users Into RMM Installs

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep…

July 20, 2026
Invoice Phish Leads to Resilient ValleyRAT

Invoice Phish Leads to Resilient ValleyRAT

A Japanese industrial manufacturer was targeted by the SilverFox group using an invoice-themed phishing email that kicked off a multi-stage malware chain. The campaign abused legitimate software and cloud services to load a malicious DLL, disable security tools, and establish remote access with…

July 31, 2026
Tech-Support Scam Drops Rogue ScreenConnect Worm

Tech-Support Scam Drops Rogue ScreenConnect Worm

Researchers found three real-world incidents where attackers tricked users into installing or running remote access tools, then used a four-step VBScript chain to deliver additional payloads. After installation, the rogue ScreenConnect client could spread the same scripts to newly connected hosts,…

September 7, 2026
RMM Phish Uses Tax & UPS Lures in 46 Countries

RMM Phish Uses Tax & UPS Lures in 46 Countries

Researchers describe a real phishing operation that tricks people into installing legitimate remote monitoring and management (RMM) tools so attackers can remotely control devices. The campaign uses familiar-looking documents (tax forms, UPS/shipping notices, Adobe PDFs, invoices, and Social…

September 3, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026