English HomeApple NewsTech NewsArabic Home
Rumor

Fake Zoom update malware campaign expands its reach to macOS

AppleInsider • Tue, 04 Aug 2026

Fake Zoom update malware campaign expands its reach to macOS

A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac. Fake Zoom update Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS package named "ZoomUpdateInstaller.pkg" to shared infrastructure. ScreenConnect is legitimate remote monitoring and management software published by ConnectWise and commonly used by IT departments. The campaign configures genuine ScreenConnect clients to contact attacker-controlled relay servers rather than an authorized company system. Once connected, the software can give an attacker remote desktop and management capabilities. The resulting activity may resemble ordinary technical support, making the intrusion harder to identify without examining how the software arrived and where it connects. Continue Reading on AppleInsider | Discuss on our Forums

What happened?

A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity. And now, it's come to Mac. Fake Zoom update Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report. They traced Windows scripts, compiled loaders, an HTML phishing page and a macOS package named "ZoomUpdateInstaller.pkg" to shared infrastructure. ScreenConnect is legitimate remote monitoring and management software published by ConnectWise and commonly used by IT departments. The campaign configures genuine ScreenConnect clients to contact attacker-controlled relay servers rather than an authorized company system. Once connected, the software can give an attacker remote desktop and management capabilities. The resulting activity may resemble ordinary technical support, making the intrusion harder to identify without examining how the software arrived and where it connects. Continue Reading on AppleInsider | Discuss on our Forums

Story details

A malware campaign is using fake Zoom updates and business files to install ScreenConnect, giving attackers remote control through software that can resemble legitimate IT activity.

And now, it's come to Mac.

Fake Zoom update Securonix researchers detailed the campaign, named Smoke#Screen, in an August 4 report.

Why it matters

This page keeps Apple rumors separate from official updates, so readers can follow early reports without confusing them with confirmed announcements.

Original source

https://appleinsider.com/articles/26/08/04/fake-zoom-update-malware-campaign-expands-its-reach-to-macos?utm_source=rss