The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.

August 4, 2026

Cyberattackers are mounting a social engineering campaign to compromise organizations via the legitimate ScreenConnect Remote Monitoring and Management (RMM) tool, in an effort that takes the RMM playbook to new frontiers.

The Smoke#Screen campaign, named by the researchers at Securonix who discovered it, uses lures related to purported Zoom and Adobe "updates," business document requests, and system-maintenance tools. Victims who execute any of the initial access files end up with a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts, according to a report published today.

While abusing RMM tools has become an increasingly common way for attackers to bypass security controls and maintain persistence on compromised systems, the campaign, which targets both Windows and macOS systems, demonstrates "a clear evolution over time," according to the Securonix researchers. Aaron Beardslee, manager of threat research at Securonix, tells Dark Reading that Smoke#Screen is distinctive for several key reasons.