Picture this: one of your staff is working through the afternoon when a pop-up appears saying Adobe or Zoom needs to update. It looks legitimate, the language is professional, and clicking “update” seems like the sensible, responsible thing to do. Except it isn’t Adobe or Zoom at all. It’s a scammer, and clicking that button just handed them the keys to your computer.
Security researchers recently uncovered a widespread campaign, nicknamed SMOKE#SCREEN, that does exactly this. Attackers are using fake update prompts, fake document review requests, and fake “system maintenance” tools to trick people into installing legitimate remote access software — most commonly a tool called ConnectWise ScreenConnect — onto business computers. Once installed, that software gives the attacker ongoing, persistent access to the machine, effectively letting them come and go as they please. As reported by The Hacker News, this campaign has been running in multiple waves, refining its lures each time to stay convincing.
What makes this attack particularly nasty for small businesses is that it doesn’t rely on some exotic technical vulnerability. It relies on trust and everyday habits. Staff are trained to keep software updated — that’s good security practice. Attackers are exploiting that exact habit against you.
The tool being installed, ScreenConnect, is not malware in the traditional sense. It’s a genuine, widely used remote monitoring and management (RMM) tool — the same type of software IT providers use legitimately to support client computers remotely. That’s precisely why it’s dangerous in the wrong hands: it looks “normal” to antivirus software and IT monitoring tools, making it much harder to detect than obvious malware. Once installed, an attacker can quietly browse files, install further malicious tools, capture keystrokes, or move across your network — all while appearing to be a legitimate remote session.
These campaigns tend to follow a familiar pattern, dressed up to look convincing:
None of these require the attacker to break into your network from the outside. They simply need one person to click one button.
Larger organisations often have dedicated security teams monitoring for unusual remote access tools appearing on their network. Most small and medium businesses in regional Victoria don’t have that luxury — IT is usually handled by a generalist staff member, an outsourced provider, or simply “whoever’s good with computers.” That gap is exactly what attackers are counting on.
There’s also a compounding risk: many small businesses already use legitimate remote access or remote support tools for their own IT management. If a fraudulent version gets installed alongside your genuine tools, it can be much harder to notice something’s wrong, because remote access itself isn’t unusual for your business — it’s just supposed to be your provider using it, not a criminal.
The good news is that this type of attack can be substantially reduced with a handful of practical habits and some sensible technical controls.
If a staff member has clicked on a suspicious update prompt, don’t wait to see if anything “looks wrong.” Disconnect the device from your network and internet immediately, change passwords for any accounts accessed from that machine, and have someone with IT security experience check for unauthorised remote access software before reconnecting it. The earlier this is caught, the less damage an attacker can do — persistent remote access gives them time to explore, and time is exactly what you want to deny them.
This campaign is a reminder that cybercriminals increasingly don’t need to “hack” their way in at all — they simply ask nicely, disguised as something routine and trustworthy. For a regional business without a large IT team watching every device around the clock, the best defence isn’t necessarily more technology. It’s a workplace culture where staff feel comfortable pausing, questioning, and double-checking before they click “update.”
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804