Skip to content

Fake Zoom update malware campaign expands its reach to macOS

A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it’s come to Mac.

Zoom update required notification window with blue smiley icon, yellow warning triangle, explanatory text, and prominent Update Zoom Now button on a dark background with green text patternsFake Zoom update

Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS package named “ZoomUpdateInstaller.pkg” to shared infrastructure.

ScreenConnect is legitimate remote monitoring and management software published by ConnectWise and commonly used by IT departments. The campaign configures genuine ScreenConnect clients to contact attacker-controlled relay servers rather than an authorized company system.

Once connected, the software can give an attacker remote desktop and management capabilities. The resulting activity may resemble ordinary technical support, making the intrusion harder to identify without examining how the software arrived and where it connects.

Continue Reading on AppleInsider | Discuss on our Forums