20/08/2026
CYBER ALERT: FAKE ADOBE & ZOOM UPDATES
Cybersecurity researchers have uncovered an active campaign dubbed SMOKE , where attackers use fake Adobe and Zoom updates, business documents, and other software-related lures to trick users into executing malicious files. The campaign ultimately installs ConnectWise ScreenConnect, a legitimate remote-management tool that is abused by attackers to establish persistent remote access to compromised computers.
This campaign demonstrates how cyber threats can hide behind familiar software, trusted cloud platforms, and seemingly routine workplace activities. A legitimate application can become a security risk when attackers manipulate users into installing or running it without authorization.
KEY FACTS
• The campaign is identified as SMOKE .
• Attackers use fake Adobe and Zoom update notifications as phishing lures.
• Business-related documents and system-maintenance themes are also used to deceive users.
• The attack chain can involve VBScript droppers, batch scripts, .NET executables, PowerShell, and malicious MSI files.
• Attackers abuse trusted services, including Dropbox and Cloudflare, to deliver or stage malicious content.
• Successful infections lead to the installation of ScreenConnect, allowing attackers to establish persistent remote access.
• Attackers may attempt to weaken security protections such as AMSI, SmartScreen, and Windows Defender.
MALICIOUS SOFTWARE AND TOOLS IDENTIFIED
• ScreenConnect – legitimate remote-management software abused to maintain persistent remote access to compromised systems.
• VBScript droppers – used to initiate the infection and download additional payloads.
• PowerShell payloads – used to retrieve and execute malicious code.
• Malicious .NET loaders/executables – used to stage and execute the next phase of the attack.
• Malicious MSI installers – used to install the ScreenConnect client.
• Batch scripts – used to modify security settings and facilitate ex*****on.
• cloudflared.exe – a legitimate Cloudflare utility observed being used as part of the attackers' infrastructure and tunneling activity.
WARNING SIGNS
• Unexpected Adobe, Zoom, or software-update notifications received through email or web pages.
• Links directing users to download updates from unfamiliar websites or file-sharing services.
• Unexpected MSI, EXE, BAT, VBScript, or other executable files attached to emails or documents.
• Requests to disable antivirus, SmartScreen, or other security controls.
• Unexpected User Access Control (UAC) administrator prompts during supposedly routine software updates.
• Appearance of an unfamiliar remote-management or remote-access application on a workstation.
• Suspicious PowerShell or cmd.exe activity following the opening of an email attachment or downloaded file.
RECOMMENDATIONS
• Never install software updates from unsolicited email links or attachments.
• Download updates only from the software vendor's official website or approved organizational repositories.
• Verify unexpected update requests with your IT or cybersecurity personnel.
• Restrict the ex*****on of untrusted MSI, EXE, BAT, and script files.
• Monitor and audit the authorized use of Remote Monitoring and Management (RMM) tools such as ScreenConnect.
• Monitor suspicious PowerShell and command-line activity.
• Maintain endpoint security controls and investigate attempts to disable or tamper with security protections.
• Enforce appropriate UAC and application-control policies to prevent unauthorized administrative actions.
Cyber attackers do not always use obviously malicious software or suspicious websites; they can disguise their activities as routine software updates and legitimate business processes. Think before you click, verify before you install, and report suspicious activity immediately, because one seemingly harmless update can provide attackers with persistent access to your system.