[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fR9_vD3I193oX8A6Qw_P4cyqFsE3a9sLsKpWLpx6SGiQ":3},{"article":4,"iocs":57},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"d8744c79-7259-4b3c-adf4-96cfea8dedd9","Phishing Abuses RMM Tools for Persistent Access","phishing-abuses-rmm-tools-for-persistent-access-53cae5","Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.","Microsoft Defender Experts observed phishing campaigns in July 2026 that used disguised MSP360 RMM installers, distributed via meeting invitations and other social engineering lures, to gain initial access. The legitimate MSP360 installer was used to deploy a ConnectWise ScreenConnect client, creating a secondary remote-access channel for threat actors to conduct post-compromise activities like information collection and credential access.","Phishing campaigns abuse MSP360 RMM to deploy ScreenConnect for persistent access.","Share Link copied to clipboard! TagsPhishingSocial engineeringContent typesResearchProducts and servicesMicrosoft DefenderMicrosoft Defender ExpertsTopicsActionable threat insightsThreat intelligence In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software. Microsoft observed the MSP360 deployment being used to download and install a ConnectWise ScreenConnect client, creating a secondary remote-access channel that provided redundant access to compromised systems. Microsoft did not observe exploitation of ScreenConnect software itself; rather, threat actors abused legitimately obtained remote administration software to establish and maintain access. After access was established, threat actors used these remote administration channels to deploy additional tools and conduct post-compromise activity, including information collection and credential-access operations. This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities. Microsoft Defender for Endpoint detects suspicious and uncommon remote-management activity, while the hunting queries and mitigations in this post can help organizations identify and restrict unapproved RMM use. Attack chain overview The observed multi-stage intrusion chain began when phishing lures delivered a legitimate, digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames. Following successful User Account Control (UAC) elevation, the installer established MSP360 services for persistent access and leveraged the RMM agent to invoke PowerShell, download, and silently install ConnectWise ScreenConnect. This effectively introduced a second remote administration channel on the compromised device, which the threat actor subsequently used to transfer and execute additional tooling supporting credential access, local data collection, and other post-compromise activity. Figure 1. Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access and follow-on activity. Initial Access: Phishing Campaign Delivering Masqueraded MSP360 RMM Installer Microsoft observed multiple phishing campaigns that used a multi-stage delivery chain to distribute legitimate, digitally signed MSP360 RMM software (v2.5.0.67). Phishing emails directed users to actor-controlled landing pages that impersonated document-sharing portals, invitation workflows, Adobe Reader download pages, Zoom installation pages, and business collaboration platforms. Upon user interaction, victims were redirected to download locations hosted on both attacker-controlled infrastructure and legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. The downloaded executables used filenames crafted to resemble legitimate business content, meeting invitations, PDF documents, and software installers. Analysis of downloaded samples showed that many ultimately contained the same MSP360 RMM installer package despite appearing as different files to the victim. MSP360 SHA256: 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc MSP360 SHA1: f34330d4c6e0aa978dc3af40360c14b31ad51127 Observed lure themes: We have observed the threat actor using multiple social-engineering themes, including: Workplace meeting requests Zoom and Google Meet installation prompts Adobe Acrobat and PDF reader updates RSVP invitations and e-cards Job offer documents Document review and signature requests DHL and package-delivery themed content Examples of observed filenames included: VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe Figure 2. Actor-controlled tax-document lure prompting download of a masqueraded MSP360 installer. Figure 3. Image displaying the execution of downloaded MSP360 RMM. The campaign relied on a diverse set of payload-hosting mechanisms. Microsoft observed the actor distributing the payload through attacker-controlled domains, websites assessed to be compromised, and legitimate cloud-hosted services. Cloud-hosted services used for payload distribution included Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. This approach enabled the actor to rapidly rotate delivery infrastructure while continuing to distribute the same MSP360 installer using different lure themes and filenames. RMM platforms are attractive to threat actors because they are designed to provide administrators with broad remote management capabilities across managed endpoints, including remote command execution, software deployment, file transfer, and persistent service-based access. When abused, these same capabilities can give threat actors a flexible post-compromise channel for maintaining access, deploying additional tooling, and conducting follow-on activity while blending in with legitimate remote administration workflows. MSP360 RMM installation and foothold establishment After victims downloaded and executed the masqueraded MSP360 installer, the binary launched from the user’s Downloads directory under a filename designed to resemble a legitimate business document. The installer subsequently dropped multiple installation components, including System.dll, nsExec.dll, and UAC.dll, to the following folder paths before relaunching itself through an elevation workflow generated by the installer framework. Next, the installer invoked a Windows User Account Control (UAC) elevation workflow. In observed successful installations, the process continued with elevated privileges, allowing deployment of MSP360 components and services. In unsuccessful installations, the elevation did not complete, and deployment terminated before the software was fully installed. Following elevation, the installer initiated the MSP360 installation workflow and recorded installation status messages using Windows eventcreate.exe. The installer generated “Begin installation” and “End installation. MSP360 de Success.” events under the event source: MSP360 RMM Agent installer. The installer dropped multiple MSP360 plugins and binaries within the installation directory: C:\\Program Files\\RMM Agent\\. The installer also performed prerequisite discovery by enumerating installed .NET runtimes using: dotnet –list-runtimes. To establish long-term access on the affected device, the installer registered two Windows services: RMM.Agent.exe & RMM.Agent.Launcher.exe. Microsoft observed events indicating stopping any existing MSP360 services and installing new MSP360 services. In addition to service-based persistence, the installer created registry-based autorun entries for MSP360 user interface components, ensuring the tray applications would automatically launch when users signed in. The installation routine also modified the Windows Firewall configuration by creating an inbound allow rule for the MSP360 agent. The rule allowed inbound UDP traffic to C:\\Program Files\\RMM Agent\\RMM.Agent.exe on port 48678. This configuration enabled network communications required by the remote management platform. Figure 4. Process execution flow of the MSP360 RMM installation. Not every execution of the installer resulted in a successful deployment. In some instances, the installe","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F09\u002F29\u002Fphishing-abuses-rmm-tools-persistent-access\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F05\u002FMS_Actional-Insights_Links.jpg","2026-09-29T21:39:27+00:00","2026-09-30T00:00:10.144115+00:00",8,[18,21,23,26,28],{"name":19,"type":20},"MSP360 RMM","product",{"name":22,"type":20},"ScreenConnect",{"name":24,"type":25},"Microsoft","vendor",{"name":27,"type":25},"ConnectWise",{"name":29,"type":30},"RMM","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":31,"icon":33,"name":34,"slug":35},null,"Threat Intelligence","threat-intelligence",[37,42,47,52],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":53},{"id":54,"icon":33,"name":55,"slug":56},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",[58,62],{"type":59,"value":60,"context":61},"hash_sha256","108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc","MSP360 RMM installer SHA256 hash",{"type":63,"value":64,"context":65},"hash_sha1","f34330d4c6e0aa978dc3af40360c14b31ad51127","MSP360 RMM installer SHA1 hash"]