SMOKE#SCREEN Campaign: Multi-Wave RMM Abuse and Evasion
Score: 9/10

SMOKE#SCREEN Campaign: Multi-Wave RMM Abuse and Evasion

The SMOKE#SCREEN campaign utilizes diverse social engineering lures and aggressive security-dismantling toolsets to deploy persistent ScreenConnect RMM agents on Windows and macOS systems.

Executive Summary

Securonix Threat Research has identified an active campaign named SMOKE#SCREEN that leverages legitimate Remote Monitoring and Management (RMM) software, specifically ScreenConnect, to gain persistent access to victim environments. The threat actor employs a sophisticated arsenal including VBScript droppers, .NET loaders, and phishing pages that impersonate Zoom updates, Adobe Flash, and business document reviews. The campaign targets both Windows and macOS platforms, demonstrating a high level of operational maintenance and adaptation.

Technical analysis reveals an evolving tradecraft that ranges from initial passive obfuscation to aggressive system neutralization. Earlier variants focused on environment keying and XOR encryption, while more recent iterations utilize compiled .NET loaders that systematically dismantle Windows Defender, bypass AMSI, and disable UAC. The final payloads are legitimate, ConnectWise-signed ScreenConnect MSIs, which allows the activity to blend in with authorized administrative traffic and evade many reputation-based security controls.

This campaign is significant due to the actor's rapid iteration cycle and explicit targeting of security products like Elastic to break event correlation. By using trusted infrastructure such as Dropbox for payload delivery and Cloudflare Quick Tunnels for anonymity, the actor successfully bypasses standard perimeter defenses. Organizations must shift toward behavioral detection of RMM abuse and endpoint tampering to mitigate this persistent threat.

Key Details

Threat Name

SMOKE#SCREEN Campaign

Affects

—

Adversary

SMOKE#SCREEN Other Adversaries and Aliases: FAMOUS CHOLLIMA

Malware/Tools

ScreenConnect, MemoryLoader.cs, loader.cs, zoom-update.vbs, RSKAdvGrpSupportingdocuments.vbs, SystemCheck, AsyncRAT, Brickstorm

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure8
Technical Depth9

Sources