Smoke#Screen Campaign Weaponizes ScreenConnect for RMM Takeovers
A threat actor tracked as "Smoke#Screen" is leveraging ConnectWise ScreenConnect and other legitimate remote monitoring and management (RMM) tooling to establish persistent footholds inside compromised corporate networks, according to researchers analyzing the campaign. The tradecraft blends diverse social-engineering lures with rapidly rotating payloads, allowing the operator to pivot from initial contact to hands-on-keyboard access in a single engagement.
The playbook, dissected in detail by Dark Reading, shows the adversary cycling through phishing emails, bogus helpdesk callbacks, fake software-update prompts, and SEO-poisoned download pages to funnel targets into running ScreenConnect clients. Once executed, the signed RMM binary grants attackers the same level of control as an IT administrator — bypassing the need for traditional malware that endpoint detection tools are tuned to catch. Operators have also been observed staging secondary payloads, including info-stealers and credential-dumping utilities, after gaining ScreenConnect access.
Defenders are urged to audit RMM deployments, enforce application allow-listing around tools like ScreenConnect, AnyDesk, and TeamViewer, and monitor for client installations originating outside standard IT channels. Network telemetry should flag outbound connections to non-corporate ScreenConnect relay servers, and SOC teams should baseline expected RMM usage across the enterprise.
For organizations wanting to validate their own external attack surface, a port scanner can quickly identify exposed RMM listeners, while a DNS leak test helps confirm whether corporate traffic is leaking through unapproved channels. Admins should also run a WHOIS lookup on suspicious relay domains to attribute infrastructure to known hosting providers commonly abused in these campaigns.