Securonix researchers have uncovered the Smoke#Screen campaign, in which attackers abuse the legitimate ScreenConnect RMM tool to gain persistent remote access to compromised Windows and macOS systems. The campaign stands out for rotating payloads between individual download sessions and using four psychologically distinct social engineering lures — fake Zoom/Adobe updates, document-review requests, and a SystemCheck maintenance tool — to maximize victim reach. Attackers inadvertently exposed their C# source code on an open directory, allowing researchers to reconstruct five kill chains and three relay servers. The threat actor layers Cloudflare tunnels, Dropbox, and ConnectWise-signed binaries to evade signature-based controls. Defenders are advised to implement behavioral EDR rules, set UAC to 'Always notify,' and monitor for unauthorized RMM installations and anomalous process relationships.