Logo

Fake Software Update Pop-Ups: A Real Threat to Your Business

Picture this: one of your staff is working through the afternoon when a pop-up appears saying Adobe or Zoom needs to update. It looks legitimate, the language is professional, and clicking “update” seems like the sensible, responsible thing to do. Except it isn’t Adobe or Zoom at all. It’s a scammer, and clicking that button just handed them the keys to your computer.

Security researchers recently uncovered a widespread campaign, nicknamed SMOKE#SCREEN, that does exactly this. Attackers are using fake update prompts, fake document review requests, and fake “system maintenance” tools to trick people into installing legitimate remote access software — most commonly a tool called ConnectWise ScreenConnect — onto business computers. Once installed, that software gives the attacker ongoing, persistent access to the machine, effectively letting them come and go as they please. As reported by The Hacker News, this campaign has been running in multiple waves, refining its lures each time to stay convincing.

Why this scam is so dangerous

What makes this attack particularly nasty for small businesses is that it doesn’t rely on some exotic technical vulnerability. It relies on trust and everyday habits. Staff are trained to keep software updated — that’s good security practice. Attackers are exploiting that exact habit against you.

The tool being installed, ScreenConnect, is not malware in the traditional sense. It’s a genuine, widely used remote monitoring and management (RMM) tool — the same type of software IT providers use legitimately to support client computers remotely. That’s precisely why it’s dangerous in the wrong hands: it looks “normal” to antivirus software and IT monitoring tools, making it much harder to detect than obvious malware. Once installed, an attacker can quietly browse files, install further malicious tools, capture keystrokes, or move across your network — all while appearing to be a legitimate remote session.

How the scam typically unfolds

These campaigns tend to follow a familiar pattern, dressed up to look convincing:

  • An email, pop-up, or fake website prompts the user to “update” Adobe Reader, Acrobat, or Zoom
  • A request to “review” an attached business document, invoice, or contract
  • A prompt to run a “system maintenance” or “cleanup” utility
  • Branding, fonts and layout that closely mimic the real software vendor

None of these require the attacker to break into your network from the outside. They simply need one person to click one button.

Why small businesses are especially at risk

Larger organisations often have dedicated security teams monitoring for unusual remote access tools appearing on their network. Most small and medium businesses in regional Victoria don’t have that luxury — IT is usually handled by a generalist staff member, an outsourced provider, or simply “whoever’s good with computers.” That gap is exactly what attackers are counting on.

There’s also a compounding risk: many small businesses already use legitimate remote access or remote support tools for their own IT management. If a fraudulent version gets installed alongside your genuine tools, it can be much harder to notice something’s wrong, because remote access itself isn’t unusual for your business — it’s just supposed to be your provider using it, not a criminal.

What you can do about it

The good news is that this type of attack can be substantially reduced with a handful of practical habits and some sensible technical controls.

  • Never update software from a pop-up or email link. Genuine updates for Adobe, Zoom and similar software should be installed via the application itself (Help > Check for Updates) or downloaded directly from the vendor’s official website — not from a link someone sent you.
  • Treat urgent “review this document” requests with suspicion, especially if you weren’t expecting them or the sender is unfamiliar. Verify by phone or a separate message if in doubt.
  • Restrict who can install software on business computers. If staff don’t have admin rights on their machines, it becomes much harder for a stray click to install anything at all.
  • Keep a known list of approved remote access tools used by your business or IT provider, and be alert to any remote access software you don’t recognise showing up in your systems.
  • Use reputable endpoint protection that can flag legitimate-but-unauthorised tools like RMM software being installed outside of normal channels, not just traditional viruses.
  • Train staff regularly, briefly and practically. A five-minute conversation about “what a fake update looks like” is often more effective than a lengthy policy document nobody reads.

If you suspect you’ve been affected

If a staff member has clicked on a suspicious update prompt, don’t wait to see if anything “looks wrong.” Disconnect the device from your network and internet immediately, change passwords for any accounts accessed from that machine, and have someone with IT security experience check for unauthorised remote access software before reconnecting it. The earlier this is caught, the less damage an attacker can do — persistent remote access gives them time to explore, and time is exactly what you want to deny them.

The bigger picture

This campaign is a reminder that cybercriminals increasingly don’t need to “hack” their way in at all — they simply ask nicely, disguised as something routine and trustworthy. For a regional business without a large IT team watching every device around the clock, the best defence isn’t necessarily more technology. It’s a workplace culture where staff feel comfortable pausing, questioning, and double-checking before they click “update.”


Worried This Could Affect Your Business?

If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.

Book your free security assessment →

Logo
Servicing small businesses across the valley.
Get in touch
Customer Support

(+61) 0412 440 804

Copyright © 2025 Maximum IT Solutions