Cybersecurity experts have uncovered a sophisticated campaign utilizing fake Adobe and Zoom update alerts to infiltrate systems with Remote Monitoring and Management (RMM) tools like ScreenConnect. This operation, identified as SMOKE#SCREEN by Securonix Threat Research, relies on social engineering techniques to deceive users into deploying malicious software.
Details of the SMOKE#SCREEN Campaign
The campaign’s strategy involves a combination of VBScript droppers, batch file loaders, and .NET executables, all connected to a staging server. This malicious activity culminates in the installation of a ScreenConnect agent, allowing attackers persistent control over infected machines. No specific threat actor has been linked to this operation yet.
Research indicates that the attackers exploit the legitimate nature of RMM tools, enabling them to bypass security measures and blend in with authorized software environments. Securonix began investigating this after identifying a server used to stage attacks and maintain control over compromised systems through a ScreenConnect relay.
How the Attacks are Executed
The initial attack vector is believed to be spear-phishing emails containing obfuscated VBScript droppers. These scripts perform checks to avoid detection by security tools and, if successful, deploy a PowerShell command to execute a C# payload. Some attacks leverage business-themed lures to trick users into initiating the malicious script.
In certain instances, a compressed archive is used to disable security features on the victim’s computer before executing the attack. This archive may contain scripts that modify system settings, disable security alerts, and escalate privileges through User Account Control prompts.
Implications and Defensive Measures
This campaign underscores the ongoing challenges faced by cybersecurity professionals in defending against sophisticated threats. Attackers continuously adapt their methods, from using encrypted scripts to deploying aggressive tactics aimed at disabling security protocols.
Organizations are advised to mitigate risks by restricting the execution of untrusted files, monitoring for suspicious process behaviors, and auditing the use of RMM tools within their networks. Ensuring strict User Account Control settings can also help prevent unauthorized actions.
Additional Threats from Fake Software
Concurrently, Bitdefender has reported another malicious campaign using fake Xeno Executor installers to deploy a Java-based information stealer. This malware targets users through gaming forums and Discord, aiming to capture sensitive data, including credentials and cryptocurrency wallets.
The malware, known as Powercat, is capable of extensive surveillance and data manipulation, posing significant risks to affected users. By exploiting the popularity of gaming cheats, attackers expand their reach and potential impact.
As cyber threats evolve, staying informed and implementing robust security practices remain critical for both individuals and organizations. Vigilance against phishing attempts and suspicious downloads is essential to safeguard against these evolving threats.
