Cybersecurity

Fake Zoom Updates Are Giving Hackers Remote Control of Your Computer

A sophisticated hacking campaign called SMOKE#SCREEN is using fake Zoom update pop-ups to silently install remote access software on victims' computers. Here's what it looks like, why it works, and how to protect yourself.

Fake Zoom Updates Are Giving Hackers Remote Control of Your Computer

You're working at your desk. A pop-up appears telling you that Zoom needs an urgent update — your secure connection is failing, and you should install the latest version immediately. The page looks right. The logo looks right. A two-second timer counts down and a download starts automatically.

You run the installer. Nothing seems to happen.

But something did happen. A hacker now has full, persistent remote access to your computer — and it looks exactly like a legitimate IT technician is logged in.

This is the SMOKE#SCREEN campaign, and it's actively targeting everyday users and businesses right now.


What Is SMOKE#SCREEN?

Security Affairs is reporting on research from Securonix Threat Research, which has been tracking an active, multi-wave hacking campaign using rotating social engineering lures — fake Zoom update prompts, fake Adobe software notices, fake business document reviews, and fake system maintenance utilities — to silently install a remote access tool called ConnectWise ScreenConnect on victim machines.

The campaign has macOS victims in its crosshairs too: a file called ZoomUpdateInstaller.pkg delivers the same payload on Macs, connecting to the same attacker-controlled servers as the Windows version.


What Is ScreenConnect, and Why Is It Dangerous in the Wrong Hands?

ScreenConnect (now branded as ConnectWise ScreenConnect) is a completely legitimate remote monitoring and management (RMM) tool. IT departments and managed service providers use it every day to remotely log in to computers, run diagnostics, and fix problems — all with the customer's knowledge and consent.

That last part is key. In normal use, you know someone is connected. In the SMOKE#SCREEN campaign, you have no idea.

Once installed, the ScreenConnect agent silently connects to an attacker-controlled relay server. According to Security Affairs, victims end up with "a fully functional ScreenConnect agent silently installed and beaconing to one of three attacker-controlled relay servers, providing the threat actor with persistent, legitimate-looking remote access to compromised hosts."

Because the final payload is a legitimate ConnectWise-signed installer — signed with a valid DigiCert certificate — many security tools treat it as trusted software. The researchers note that "many EDR products apply reduced scrutiny to binaries signed by recognized enterprise software vendors." The attackers chose ScreenConnect specifically because of this.


How the Fake Zoom Update Page Works

The phishing page the attackers built isn't a sloppy knock-off. Security Affairs reports that Securonix researchers found it uses the correct Zoom logo SVG file, the correct brand color hex code, a fake version number, and urgency messaging about secure connections failing. A JavaScript timer triggers an automatic download after just two seconds — no click required. The page then instructs you to run the downloaded file to complete the update.

By the time you do, the attacker already has a relay server waiting for your computer to check in.

The campaign also hosts its malicious files on trusted platforms like Dropbox and uses Cloudflare tunnels to deliver payloads — specifically because those services are allow-listed in most corporate firewall configurations and rarely raise flags.


This Attacker Is Actively Learning and Adapting

What makes SMOKE#SCREEN especially concerning is how quickly the people behind it respond to defenders.

Early versions of the attack used cautious, encrypted scripts with environment checks that would abort if the computer had less than 2 GB of RAM or had analysis tools like Wireshark running — a classic sign of someone trying to avoid security researchers.

Later versions went the opposite direction: aggressively disabling Windows Defender, patching Windows' built-in malware scanning (AMSI) out of memory, adding the entire C:\ drive as a Defender exclusion, and stopping the Windows Defender service permanently — all within 15 seconds of execution.

Then, when security tools started catching that behavior, the attackers pivoted again. The newest version of the malware avoids detection entirely rather than destroying defenses. Most tellingly, Security Affairs reports that researchers found a comment left in the source code: // WAIT 3 MINUTES (Breaks Elastic correlation) — a deliberate 180-second sleep command designed specifically to break the event correlation windows used by commercial security platforms.

This is a threat actor watching what works, watching what gets caught, and publishing cleaner code in response. That's not a script kiddie. That's a capable, actively maintained operation.


The Golden Rule: Never Update Software From a Pop-Up

This attack lives and dies on one moment: getting you to run an installer that didn't come from the real Zoom website or the Zoom app itself.

Here's the rule that prevents it, and it applies to every piece of software you use:

Never update an application by clicking a pop-up, a link in an email, or a button on a webpage you didn't deliberately navigate to. Always update software from inside the application itself, or by going directly to the official website by typing the address yourself.

For Zoom specifically:

  • Open the Zoom desktop app
  • Click your profile picture in the top-right corner
  • Select Check for Updates

That's it. If Zoom needs an update, the app will tell you — inside the app. A webpage telling you to download and run an installer is not a Zoom update. It's an attack.

The same logic applies to Adobe, Windows, your browser, your antivirus software, and anything else. Legitimate software updaters don't ask you to download a mystery MSI file from a link. They update themselves.


What to Watch for on Your Own Computer

If you're wondering whether something unauthorized might already be running on your machine, here are some red flags to look for:

  • ScreenConnect or ConnectWise Remote installed without you knowing it. Check your installed programs list (Start ? Settings ? Apps).
  • Unusual network activity. ScreenConnect agents "beacon" to their relay servers regularly. A persistent outbound connection to an IP address (rather than a company domain) is a warning sign.
  • Windows Defender suddenly disabled or showing errors you didn't cause.
  • Your computer acting sluggish or showing unusual cursor movement when you're not doing anything — someone else may be at the keyboard.

This is also a good reminder of why keeping Windows up to date matters. The Microsoft Security Blog recently published a case study showing how Microsoft Defender's automated attack disruption stopped

Related local service
Worried this could be malware?
If your computer has pop-ups, redirects, suspicious downloads, or ransomware warnings, start with our local virus removal page.
Tags
cybersecurity vulnerability small-business-it web-security windows-security
Call Now