Hackers Use Fake Adobe and Zoom Updates to Control Computers — What Happened

Hackers Use Fake Adobe and Zoom Updates to Control Computers — What Happened

Fake Adobe and Zoom updates are installing remote-access software on Windows computers. Here’s how the phishing campaign works and what you can do to keep attackers away from your device.

What Happened?

According to The Hacker News, researchers found an active phishing campaign using fake Adobe and Zoom updates to install ScreenConnect.

The report was published on August 4, 2026. Securonix researchers named the campaign SMOKE#SCREEN.

The attackers also used fake business document reviews and system maintenance tools. These files were mainly delivered through phishing emails.

Opening one of the files could install ScreenConnect. This legitimate program allows IT workers to provide remote computer support.

However, the attackers used it to open remote desktop sessions and maintain access to infected computers. The campaign has not been linked to a known criminal group.

The report does not confirm that personal information was stolen. However, remote access may put your saved files, passwords, and browser sessions at risk.

Your information may also have been leaked in other incidents without you knowing. Automatic monitoring can help you spot these problems earlier.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Targeted and What Information Was at Risk?

Securonix believes the attackers used spear-phishing. This means they sent carefully written emails to specific recipients or organizations.

The report did not identify the targeted companies, countries, or individuals. It also did not say how many computers were infected.

Researchers did not confirm what information the attackers viewed or stole.

However, ScreenConnect can provide control over a computer. Attackers may be able to view files, open programs, and use services already logged in.

Check if your email was found in a leak

Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.

Run a free check

How Fake Adobe and Zoom Updates Installed ScreenConnect

The attacks usually began with an email offering a software update, document review, or computer maintenance tool.

Some emails contained a VBScript file. A script is a set of instructions that tells a computer to perform certain actions.

The script first checked for tools commonly used by security researchers. It stopped running when it detected programs such as Wireshark or VirtualBox.

If those programs were absent, the script used PowerShell to download more harmful code. PowerShell is a legitimate Windows tool used to run commands.

Another version tried to turn off Windows security protections. It also displayed an administrator approval request before running the ScreenConnect installer.

The attackers sometimes hosted files through Dropbox. They also used temporary Cloudflare links, which could make the downloads appear more trustworthy.

After installation, ScreenConnect contacted an attacker-controlled server. This connection allowed the operators to open a remote desktop and maintain access.