Smoke#Screen Attack Uses Social Engineering and ScreenConnect for Persistent Access
Learn how remote monitoring tools can be weaponized and what defenders can do to detect such intrusions.
A campaign tracked as Smoke#Screen is using diverse social engineering lures and rotating payloads to deliver ScreenConnect, a legitimate remote monitoring and management (RMM) tool, for persistent remote access to compromised networks. The attackers rely on tricking users into installing the software, which then gives them ongoing control over the victim's system. The playbook highlights how threat actors repurpose trusted administrative tools to blend in with normal network activity.
The exact targets and scale of the campaign are not detailed in available reporting, but the technique is well-known in cybersecurity circles: using RMM tools for unauthorized access is a form of "living off the land" that makes detection harder because the software itself is not malicious.
Why it matters
This attack pattern shows that even legitimate tools can become dangerous when placed in the wrong hands. As organizations increasingly rely on remote access solutions for IT support, attackers are following suit. The Smoke#Screen campaign underscores the need for robust monitoring of RMM tool usage and user awareness training to spot social engineering attempts.
This attack pattern shows that even legitimate tools can become dangerous when placed in the wrong hands.
Social engineering lure
Attacker sends a convincing message (e.g., fake IT support) to the target.
User installs ScreenConnect
Victim is tricked into downloading and running the legitimate RMM tool.
Persistent remote access
Attacker gains ongoing control over the compromised system.
Lateral movement
What you can learn from this
- Social engineering lures are the entry point: Attackers craft convincing messages—often posing as IT support, vendors, or colleagues—to trick users into installing software. As a learner, practice identifying red flags in unsolicited requests: urgency, unexpected attachments, or requests to install remote access tools. Always verify through a separate communication channel.
- RMM tools are a double-edged sword: ScreenConnect and similar tools are designed for legitimate remote administration, but attackers abuse them to gain persistent access. Understand that any tool with remote execution capability should be treated as a high-risk asset. Implement application allowlisting so only approved RMM instances can run, and monitor for unusual installation patterns.
- Rotating payloads complicate signature-based detection: The attackers change their payloads frequently, which means antivirus signatures alone are insufficient. Learn about behavioral detection: look for processes that spawn network connections shortly after installation, or RMM tools running outside normal business hours. Practise using a sandbox to analyze suspicious files.
- Network segmentation limits blast radius: If an attacker gains access via RMM, segmentation can prevent them from moving laterally to critical systems. As a hands-on exercise, map out trust boundaries in a sample network and configure firewall rules to restrict RMM traffic to only authorized management subnets.
- User training is a critical control: Since the attack starts with a user action, education is key. Teach users to never install software requested via email or chat without direct verbal confirmation from IT. Simulate phishing campaigns to build awareness and measure improvement.
We teach this
Sources
Our reporting is an original summary; full coverage is at the links above.
Don't just read about it — build it.
Square 1 teaches the skills behind the headlines, with every line of your work graded by AI. Find your starting point in 3 minutes.
Get your free skill report