HeadlinesBriefing favicon HeadlinesBriefing.com

Fake Zoom Update Malware Hits macOS

AppleInsider •
×

A malware campaign called Smoke#Screen is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac.

Securonix researchers detailed the campaign in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS package named "ZoomUpdateInstaller.pkg" to shared infrastructure.

ScreenConnect is legitimate remote monitoring and management software published by ConnectWise and commonly used by IT departments. The campaign configures genuine ScreenConnect clients to contact attacker-controlled relay servers rather than an authorized company system.

Once connected, the software can give an attacker remote desktop and management capabilities. The resulting activity may resemble ordinary technical support, making the intrusion harder to identify without examining how the software arrived and where it connects. The macOS package contacted the same primary relay server as several Windows payloads, tying it to the wider operation.

However, Securonix did not identify how the Mac installer was distributed or report any confirmed Mac infections. The report also didn't say whether the macOS package was signed and notarized by Apple. The discovery therefore establishes that the campaign's infrastructure included a Mac payload, but not that attackers successfully delivered it to Mac users.