"The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0[.]143:8080," researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared with The Hacker News.
How SMOKE#SCREEN delivers persistent ScreenConnect access
Securonix Threat Research has catalogued a multi-wave campaign, codenamed SMOKE#SCREEN, that uses social-engineering lures — fake Adobe and Zoom updates, business document reviews, and system maintenance decoys — to push victims toward an installer for ConnectWise ScreenConnect. Initial access is assessed to be spear-phishing: emails deliver an obfuscated Visual Basic Script (VBScript) dropper that performs environment and anti-analysis checks, enumerates running processes, and aborts if diagnostic or virtualization tools such as wireshark.exe, procmon.exe, vboxservice.exe, vmtoolsd.exe, xenservice.exe, or fiddler.exe are present.
If those checks pass, the VBScript decrypts a PowerShell command that fetches a C# payload from 207.189.11[.]170 and executes it; alternate paths include business-themed VBScript or a compressed archive that runs a batch script. The batch variant performs an aggressive sequence: disabling Windows Antimalware Scan Interface (AMSI), prompting for User Account Control (UAC) elevation, modifying the Registry to turn off SmartScreen protections, removing the Zone.Identifier alternate data stream from the downloaded MSI, and then executing the MSI. All roads lead to the same end state: a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, allowing remote desktop sessions and persistent access.
Infrastructure: WsgiDAV staging, Cloudflare Quick Tunnel, and trusted hosts
Securonix traced a live WsgiDAV-based staging server at 207.174.0[.]143:8080 that served both as a payload host and as a command-and-control plane via a ScreenConnect relay on port 8041. The analysis uncovered three distinct C2 clusters, each tied to different decoy binaries (software update, document review, document viewer).
The actor also makes tactical use of trusted hosting and ephemeral tunnels. An early phishing page ('zoom-update.html') delivered payloads via a Dropbox shared link — a technique Securonix says can bypass domain-reputation filters because Dropbox is commonly allow-listed. A compiled .NET loader ('MemoryLoader.cs') references a Cloudflare Quick Tunnel host (subscription-magnetic-recommended-meat.trycloudflare.com) and the staging server runs cloudflared.exe, indicating the attacker uses Cloudflare’s binary to create temporary exposure for local services.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Tradecraft evolution and the challenge of legitimate RMM abuse
Securonix highlights an observable arc in the actor’s tradecraft: from cautious XOR-encrypted VBScript droppers to an aggressive "nine-step Defender destruction" sequence, and then a return to stealth with anti-EDR timing and self-contained encrypted bundles. "What makes this campaign particularly notable for defenders is the observable arc of the actor's tradecraft," Securonix wrote, emphasizing the real‑time adaptation between attacker and defender.
The report underscores a central problem: by installing a legitimate Remote Monitoring and Management (RMM) client like ScreenConnect, an attacker can bypass many security controls and blend into enterprise tooling without needing a bespoke remote-access trojan. The activity has not been attributed to any known threat actor or group.
What this means for security teams, procurement leaders, and end users
- Security teams: Securonix recommends restricting execution of untrusted MSI files, monitoring for processes that attempt to tamper with security products, auditing legitimate use of RMM tools, watching for suspicious PowerShell and cmd.exe processes, and enforcing strict UAC settings to prevent standard users from bypassing elevation prompts.
- Procurement leaders and IT ops: The campaign shows risk in allow-listing third-party hosting (for example, Dropbox) and in the legitimate spread of RMM tools that can be repurposed by attackers; auditing who can deploy and configure RMM clients is a practical control called out by the researchers.
- End users: The lures are familiar — update prompts and business document reviews — and users are directly targeted by spear-phishing that hands off execution to VBScript and batch loaders. Treat unexpected update requests and unsolicited document links with heightened skepticism.
Parallel gaming lure: fake Xeno Roblox cheats and the Powercat stealer
Bitdefender separately disclosed a distinct but thematically related campaign that uses fake Xeno Executor installers promoted on gaming forums and Discord to start a multi-stage Java infection chain. The final payload, a stealer named Powercat, is capable of credential theft, browser cookie and cryptocurrency-wallet harvesting, recording keystrokes, accessing webcams, streaming desktops, file manipulation, and granting interactive remote control.
The Bitdefender analysis says the chain checks for a Java Runtime Environment and, if missing, extracts one; it reads a local file ("XenoIcon.jpg") to retrieve keys needed to validate with a C2 at solthere[.]net, then launches an obfuscated JAR disguised as "decompiler.exe" that eventually downloads the Java-based stealer. Targeted software ranges from browsers (Brave, Chrome, Edge, Opera series, Vivaldi) to wallets (Atomic, Exodus, Monero Wallet, et al.), development tools, game launchers, VPNs, and messengers. To target Exodus specifically, the stealer checks for Exodus version 26.1.5 and injects JavaScript into app.asar to capture tokens. Bitdefender said the activity has been ongoing since the start of 2026 with a surge in the second half of March; ThreatLocker documented aspects of it in late March 2026.
Both disclosures underline a shared theme: adversaries are weaponizing trust — trusted hosting, trusted tools, and trusted lures — to achieve persistent access. Securonix’s tactical recommendations remain direct and actionable for defenders; whether organizations will operationalize tighter controls on MSI execution, RMM ownership, and allow-listed services will determine how effectively this campaign can be contained.




