Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyber Attacks Leverage Fake Software Updates for Remote Access

Cyber Attacks Leverage Fake Software Updates for Remote Access

Posted on August 4, 2026 By CWS

Cybersecurity experts have uncovered a sophisticated campaign utilizing fake Adobe and Zoom update alerts to infiltrate systems with Remote Monitoring and Management (RMM) tools like ScreenConnect. This operation, identified as SMOKE#SCREEN by Securonix Threat Research, relies on social engineering techniques to deceive users into deploying malicious software.

Details of the SMOKE#SCREEN Campaign

The campaign’s strategy involves a combination of VBScript droppers, batch file loaders, and .NET executables, all connected to a staging server. This malicious activity culminates in the installation of a ScreenConnect agent, allowing attackers persistent control over infected machines. No specific threat actor has been linked to this operation yet.

Research indicates that the attackers exploit the legitimate nature of RMM tools, enabling them to bypass security measures and blend in with authorized software environments. Securonix began investigating this after identifying a server used to stage attacks and maintain control over compromised systems through a ScreenConnect relay.

How the Attacks are Executed

The initial attack vector is believed to be spear-phishing emails containing obfuscated VBScript droppers. These scripts perform checks to avoid detection by security tools and, if successful, deploy a PowerShell command to execute a C# payload. Some attacks leverage business-themed lures to trick users into initiating the malicious script.

In certain instances, a compressed archive is used to disable security features on the victim’s computer before executing the attack. This archive may contain scripts that modify system settings, disable security alerts, and escalate privileges through User Account Control prompts.

Implications and Defensive Measures

This campaign underscores the ongoing challenges faced by cybersecurity professionals in defending against sophisticated threats. Attackers continuously adapt their methods, from using encrypted scripts to deploying aggressive tactics aimed at disabling security protocols.

Organizations are advised to mitigate risks by restricting the execution of untrusted files, monitoring for suspicious process behaviors, and auditing the use of RMM tools within their networks. Ensuring strict User Account Control settings can also help prevent unauthorized actions.

Additional Threats from Fake Software

Concurrently, Bitdefender has reported another malicious campaign using fake Xeno Executor installers to deploy a Java-based information stealer. This malware targets users through gaming forums and Discord, aiming to capture sensitive data, including credentials and cryptocurrency wallets.

The malware, known as Powercat, is capable of extensive surveillance and data manipulation, posing significant risks to affected users. By exploiting the popularity of gaming cheats, attackers expand their reach and potential impact.

As cyber threats evolve, staying informed and implementing robust security practices remain critical for both individuals and organizations. Vigilance against phishing attempts and suspicious downloads is essential to safeguard against these evolving threats.

The Hacker News Tags:Adobe, Bitdefender, cyber threat, Cybersecurity, fake software updates, Malware, Phishing, remote access, RMM tools, ScreenConnect, Securonix, software updates, Zoom

Post navigation

Previous Post: Six RCE Vulnerabilities Threaten AI Workflow Servers
Next Post: CISO Insights: Russ Kirby on Passion and Leadership

Related Posts

SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass SolarWinds Fixes Four Critical Web Help Desk Flaws With Unauthenticated RCE and Auth Bypass The Hacker News
Rethinking AI Data Security: A Buyer’s Guide  Rethinking AI Data Security: A Buyer’s Guide  The Hacker News
Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign The Hacker News
AI-Driven Cyber Attacks Surge in 2025 AI-Driven Cyber Attacks Surge in 2025 The Hacker News
Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors Dutch NCSC Confirms Active Exploitation of Citrix NetScaler CVE-2025-6543 in Critical Sectors The Hacker News
Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OWASP Unveils Subtractive Security Top 10 for Cyber Defense
  • Key Cybersecurity Announcements at Black Hat USA 2026
  • DarkSword iOS Exploit Impacts 180 Websites and 27 Servers
  • CISO Insights: Russ Kirby on Passion and Leadership
  • Cyber Attacks Leverage Fake Software Updates for Remote Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark