A new Securonix report warns that cybercriminals are exploiting trusted software brands and sophisticated social engineering tactics to install remote access tools, targeting both Windows and macOS users while evading traditional security defences.
Cybersecurity researchers have uncovered a sophisticated malware campaign that impersonates software updates from well-known brands such as Adobe and Zoom to gain remote access to users' computers. According to a report by Securonix Threat Research, the operation relies on deceptive social engineering techniques instead of exploiting software vulnerabilities, making it difficult for users to distinguish legitimate updates from malicious ones.
The campaign employs a variety of lures, including counterfeit Zoom update notifications, fake Adobe installers, business document review requests and system maintenance utilities. While the themes vary depending on the intended target, the objective remains the same: convincing victims to install malware that silently grants attackers long-term remote access to compromised systems.
Researchers began investigating the campaign after identifying a malicious VBScript file disguised as a Zoom update. Further analysis led to an active staging server hosting multiple malicious payloads. By tracing the campaign's infrastructure, the team reconstructed five separate attack chains and identified several attacker-controlled relay servers used to manage infected devices.
Trusted software brands exploited to deceive users
One of the campaign's primary tactics involves replicating the appearance of legitimate software update pages. In one example, attackers created a fraudulent Zoom update webpage featuring authentic-looking branding, logos and version information. Visitors were warned that their Zoom application was outdated and required an urgent security update before they could continue using the service.
The fake page automatically initiated a download within seconds and displayed a convincing installation progress bar. Instead of delivering a genuine software update, users downloaded a malicious installer hosted on a trusted cloud storage platform, increasing the likelihood of bypassing email and web security filters.
Securonix also identified phishing pages masquerading as Adobe software updates, along with executables named to resemble legitimate maintenance utilities such as "AdobeReader_Update.exe" and "SystemCheck." These files prompted users to grant administrative privileges, after which the malware attempted to weaken system security before installing the final payload.
Attackers refine techniques to evade detection
The report highlights that the threat actors continuously modified their malware to avoid detection. Earlier versions relied on obfuscated scripts capable of identifying virtual machines and security analysis environments before terminating execution. More recent variants focused on disabling or bypassing Microsoft Defender protections, altering Windows security settings and removing traces of malicious downloads.
Researchers also observed a shift in strategy, with newer malware delaying execution for several minutes after installation to reduce the chances of being detected by endpoint security solutions. The attackers also leveraged Cloudflare Quick Tunnel services to deliver payloads while maintaining persistence on compromised systems.
In every observed attack, the final payload installed was ConnectWise ScreenConnect, a legitimate remote administration platform widely used by IT teams. Because the software is digitally signed and commonly deployed in enterprise environments, its presence may not immediately trigger security alerts. Once installed, it established connections to attacker-controlled servers, enabling remote access without the victim's knowledge.
The campaign also extended beyond Windows, with researchers discovering a fake macOS installer designed to infect Apple devices using similar tactics.
Securonix recommends organisations strengthen application control policies, closely monitor attempts to disable security protections, maintain an inventory of authorised remote management tools and deploy behavioural detection mechanisms capable of identifying suspicious installer activity before attackers establish persistent access.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




