Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
Threat actors are using varied social engineering lures and rotating payloads to deploy ScreenConnect, enabling persistent remote access to compromised networks.
Threat actors are using a campaign called Smoke#Screen, deploying diverse social engineering lures and rotating payloads to deliver ScreenConnect remote monitoring software. This grants them persistent remote access to compromised networks. The attackers continually change their methods to evade detection, leveraging the legitimate RMM tool for malicious takeover. The playbook exposes common tactics: initial compromise via phishing or other lures, payload rotation, and establishing long-term backdoor access through ScreenConnect. Organizations should monitor for unauthorized ScreenConnect installations and train employees to recognize evolving social engineering schemes.