Executive Summary
Securonix Threat Research has identified an active campaign named SMOKE#SCREEN that leverages legitimate Remote Monitoring and Management (RMM) software, specifically ScreenConnect, to gain persistent access to victim environments. The threat actor employs a sophisticated arsenal including VBScript droppers, .NET loaders, and phishing pages that impersonate Zoom updates, Adobe Flash, and business document reviews. The campaign targets both Windows and macOS platforms, demonstrating a high level of operational maintenance and adaptation.
Technical analysis reveals an evolving tradecraft that ranges from initial passive obfuscation to aggressive system neutralization. Earlier variants focused on environment keying and XOR encryption, while more recent iterations utilize compiled .NET loaders that systematically dismantle Windows Defender, bypass AMSI, and disable UAC. The final payloads are legitimate, ConnectWise-signed ScreenConnect MSIs, which allows the activity to blend in with authorized administrative traffic and evade many reputation-based security controls.
This campaign is significant due to the actor's rapid iteration cycle and explicit targeting of security products like Elastic to break event correlation. By using trusted infrastructure such as Dropbox for payload delivery and Cloudflare Quick Tunnels for anonymity, the actor successfully bypasses standard perimeter defenses. Organizations must shift toward behavioral detection of RMM abuse and endpoint tampering to mitigate this persistent threat.
Key Details
Threat Name
SMOKE#SCREEN Campaign
Affects
—
Adversary
SMOKE#SCREEN Other Adversaries and Aliases: FAMOUS CHOLLIMA
MITRE Techniques
Malware/Tools
ScreenConnect, MemoryLoader.cs, loader.cs, zoom-update.vbs, RSKAdvGrpSupportingdocuments.vbs, SystemCheck, AsyncRAT, Brickstorm
