Microsoft has issued an alert regarding new phishing strategies that employ MSP360’s Remote Monitoring and Management (RMM) software. These campaigns deceive users with meeting invitations, PDF themes, and software update prompts, aiming to gain unauthorized access.
Exploiting Legitimate Software
Once the misleading MSP360 installer is executed, it sets up remote management on the target systems, allowing attackers to establish an initial foothold. This foothold is then used to deploy the ConnectWise ScreenConnect client, granting further remote access to the compromised devices.
These tactics enable the attackers to introduce additional tools and conduct data collection and credential harvesting operations. Currently, no specific threat actor or group has been identified as responsible for these activities.
Multi-Stage Intrusion Chain
The intrusion process, first detected by Microsoft in July 2026, starts with phishing emails that distribute a digitally signed MSP360 RMM installer under various deceptive names. Examples include ‘VIP_ECARD_INVITATION_rmm_v2.5.0.67’ and ‘ZoomSetup_Installation_v2.5.0.67’.
The installer files are hosted on both attacker-controlled platforms and legitimate cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Once executed, the installer deploys multiple DLLs and utilizes Windows User Account Control (UAC) for elevated access, ensuring persistent presence by leveraging RMM functionalities.
Remote Access and System Manipulation
Further actions involve enumerating installed .NET runtimes, registering Windows services, and creating autorun entries to ensure MSP360 launches automatically. The setup also modifies the Windows Firewall to allow traffic to MSP360 on a specific port, enhancing persistent access.
Attackers use the dual-RMM setup to hide malicious operations within typical remote administration tasks, facilitating the delivery and execution of additional payloads via ScreenConnect’s RunFile feature. Microsoft also noted similar attacks using Faronics Deploy Agent as an alternative to MSP360, demonstrating the versatility of these threat actors.
This incident underscores how malicious entities exploit legitimate software to integrate seamlessly into standard IT operations, maintaining long-term access while minimizing detection risks. The combination of MSP360 and ScreenConnect provides robust remote administration capabilities, enabling further manipulation and control over targeted systems.
