
Fake Adobe and Zoom Updates Deploy ScreenConnect for Covert Persistent Access
Attackers are mimicking software update prompts for Adobe products and Zoom to install the legitimate remote tool ScreenConnect, enabling long-term backdoor access. Website administrators and developers are prime targets…
A new social engineering campaign is tricking users with fraudulent update notifications masquerading as Adobe Flash, Adobe Acrobat, or Zoom installers. Instead of delivering security patches, these fake pop-ups download and execute the remote administration tool ScreenConnect—often used legitimately by IT teams but repurposed here to give attackers persistent, stealthy control over compromised systems.
ScreenConnect (now rebranded as ConnectWise Control) is a powerful remote desktop solution that, once installed, can run silently in the background. Because it is signed and widely trusted, security software rarely flags it. This ‘living-off-the-land’ approach allows adversaries to bypass many endpoint defenses, maintaining a persistent foothold for data theft, lateral movement, or deploying further malware.
For website owners and developers, the risks are severe. A compromised workstation can lead to stolen FTP or hosting panel credentials, allowing attackers to deface sites, inject malicious scripts, or exfiltrate databases. Even a developer’s local test environment, if infected, can serve as a launchpad for supply-chain attacks against plugins, themes, or client sites. The persistence of ScreenConnect means the access can remain undetected for weeks or months, enabling continuous monitoring and exploitation.
To defend against such threats, user education remains paramount—always verify update sources and avoid launching installers from pop-ups. Additionally, enforcing application whitelisting and multi-factor authentication on all hosting and development accounts limits damage after a compromise. For those managing websites, relying on a hosting platform that bakes in proactive security measures, such as AEU Hosting with its managed WordPress environment and real-time threat monitoring, provides a crucial safety net that can detect and block unauthorized changes even when local machines are breached.