< Back to all clusters
[TECHNOLOGY] · 9 sources

Fake Zoom/Adobe Updates Install ScreenConnect Backdoor

Security researchers at Securonix uncovered a campaign that distributes malicious installers masquerading as Zoom or Adobe updates. The payload is a legitimate ConnectWise ScreenConnect client that, once installed on macOS or Windows, connects to attacker‑controlled relays and provides persistent remote‑desktop access.

The operation uses trusted services such as Dropbox, Cloudflare Quick Tunnel and a WsgiDAV server to host the payloads. Attackers employ social‑engineering lures—fake software updates, document‑review requests, or maintenance pretenses—to trick users into running the installer. On Windows, additional techniques disable AMSI, modify SmartScreen settings, and evade endpoint protection before launching the ScreenConnect client. The campaign is not currently linked to any known threat group.

Defenders are advised to inventory authorized remote‑management tools, monitor for unexpected ScreenConnect services or outbound connections, and watch for suspicious PowerShell, MSI execution, or tampering with security controls. Isolating affected systems, preserving logs, and resetting compromised credentials are recommended response steps.

Entities: Adobe Inc. · ScreenConnect · Securonix · Zoom Video Communications, Inc.