Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Hackers are tricking users into installing ScreenConnect, a Remote Monitoring and Management (RMM) tool, disguised as updates for Adobe and Zoom software. This campaign uses social engineering tactics, preying on users' fears of system failures and software updates.

A group of threat actors has been exploiting unsuspecting users with a sophisticated campaign that leverages the trust users have in Adobe and Zoom software updates. The campaign involves fake alerts and notifications that appear to be legitimate updates for Adobe Acrobat and Zoom Client, prompting users to download and install a Remote Monitoring and Management (RMM) tool called ScreenConnect. Once installed, ScreenConnect provides persistent remote access to the compromised systems, allowing the attackers to maintain control and conduct further malicious activities.

According to cybersecurity researchers, the campaign began in late 2021 and has been ongoing, with multiple waves of attacks reported. The attackers have been using various tactics to evade detection, including spoofing legitimate update notifications and using compromised email accounts to send the malicious attachments.

Researchers have identified the ScreenConnect RMM tool as the primary payload, which is used to establish persistent remote access to the compromised systems. The tool is designed to be highly flexible, allowing attackers to customize the level of access and control they have over the compromised systems.

The attackers are using a combination of social engineering and technical tactics to carry out this campaign. By tricking users into installing ScreenConnect, the attackers can maintain control over the compromised systems and conduct further malicious activities, such as data exfiltration, ransomware attacks, and other types of cybercrime.

Source: The Hacker News