MSP360
Microsoft has warned about phishing campaigns that distribute an installer for MSP360 Remote Monitoring and Management software, and the lures are the usual mix of meeting invitations, PDF-themed documents, software update prompts, and other social engineering content that looks harmless at a glance.
The Microsoft Security Research team said that once executed, the legitimate MSP360 installer, distributed under a deceptive file name, established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software.
That foothold is then used to download and install a ConnectWise ScreenConnect client, which gives the threat actors a redundant remote access channel to the compromised endpoint, and the access is then abused to deliver additional tools and carry out information collection and credential access operations, though the activity has not been attributed to any known threat actor or group.
Quick Summary
|
What |
Details |
|
Campaign |
MSP360 RMM phishing |
|
Lures |
Meeting invites, PDF themes, update prompts |
|
Primary Tool |
MSP360 RMM v2.5.0.67 |
|
Secondary Tool |
ConnectWise ScreenConnect |
|
Detection |
July 2026 |
|
Attribution |
None |
How the Infection Starts
The multi-stage intrusion chain, which Microsoft detected in July 2026, begins with phishing emails distributing a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive names that are designed to look like ordinary business documents.
Some of the file names Microsoft listed include VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe, PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe, RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe, and SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe.
The installer packages are staged on attacker-controlled infrastructure and on legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase, which is a pattern we see often because it makes the download look less suspicious.
What the Installer Does
Once launched, the installer drops multiple DLLs, relaunches itself by invoking the Windows User Account Control elevation workflow to run in a privileged context, establishes persistent access by deploying MSP360, and leverages the RMM tool to execute PowerShell for stealthily installing ScreenConnect.
The installer also enumerates installed .NET runtimes, registers two Windows services called RMM.Agent.exe and RMM.Agent.Launcher.exe, and creates Registry-based autorun entries to ensure that MSP360 launches automatically when users sign in to the machine.
It also modifies the Windows Firewall configuration to allow inbound UDP traffic to MSP360 on port 48678, which is the kind of change that might go unnoticed on a busy endpoint.
Why the Dual RMM Approach Works
The dual RMM remote access attack enables the attacker to transfer additional executables and facilitate post-compromise activity, while camouflaging malicious activity within regular remote administration workflows, and the payloads are run through ScreenConnect's native RunFile functionality.
Microsoft said it also observed a separate set of attacks in July 2026 that switched MSP360 for Faronics Deploy Agent to find a way in, and then used it to download and install ScreenConnect, which suggests the threat actors are experimenting with multiple RMM tools for remote access.
That detail matters, because it means defenders cannot simply block one RMM product and assume the problem is solved, and it also means the tradecraft is still evolving.
What Microsoft Says About the Trend
Microsoft said this activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities.
The company also said the combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion.
That is a clear warning that legitimate tools are the new cover story, and it is consistent with a broader pattern of attackers living off trusted software rather than relying on custom malware.
What You Should Do
- Warn users about phishing emails that contain executable attachments disguised as meeting invites, PDF documents, or software updates, because no legitimate meeting invitation requires running an installer.
- Block or monitor the specific file names Microsoft listed, since they are the fingerprints of this campaign.
- Audit endpoints for unexpected MSP360 and ScreenConnect installations, especially on machines where those tools are not approved.
- Check for the two services RMM.Agent.exe and RMM.Agent.Launcher.exe, and look at Registry autorun entries tied to MSP360.
- Review firewall changes on endpoints, particularly inbound UDP rules on port 48678 that you did not create.
- Consider a policy that requires approval before any RMM tool can be installed, because these tools are powerful and often overlooked.
- Monitor for PowerShell execution that installs remote access software, which is the exact behavior this campaign relies on.
The Bottom Line
Microsoft is warning about a phishing campaign that installs legitimate MSP360 RMM software under deceptive file names, then adds ConnectWise ScreenConnect for redundant remote access, and the pattern of abusing trusted administrative tools is becoming standard, so defenders need to treat RMM installations as a security event rather than a routine IT task.
Quick Reference
|
Key Point |
Detail |
|
Campaign |
MSP360 RMM phishing |
|
Lures |
Meeting invites, PDF themes, update prompts |
|
Primary Tool |
MSP360 RMM v2.5.0.67 |
|
Secondary Tool |
ConnectWise ScreenConnect |
|
Alternate Tool |
Faronics Deploy Agent |
|
Port |
UDP 48678 |
|
Attribution |
None |
What to Do
- Warn users about executable attachments
- Block the listed file names
- Audit endpoints for MSP360 and ScreenConnect
- Check for RMM.Agent services and autorun entries
- Review firewall rules on port 48678
- Require approval for RMM installation
- Monitor PowerShell installing remote access tools
FAQ Section
What is the MSP360 phishing campaign?
It is a campaign where attackers send phishing emails with deceptive file names containing a legitimate MSP360 RMM installer, which establishes remote access, then installs ConnectWise ScreenConnect as a second channel.
What causes infections among victims?
A phishing email arrives containing an executable file hidden in a meeting invitation, PDF file, or software update, which installation will lead to the deployment of the RMM software.
Why is this difficult to detect?
The reason for this is because MSP360 and ScreenConnect are both legitimate and digitally-signed products, meaning that their operation can appear to be routine IT work.
Any other RMM tool is used in the attacks?
Yes, Microsoft found attacks leveraging the Faronics Deploy Agent tool in place of MSP360.
What should I do if I use RMM?
Notify the users, block the file names, investigate for any unusual installation, look for RMM.Agent service and autostart entries, and examine firewall rules on port 48678.
Does it have an attribution?
No, the activity has not been attributed to any known threat actor.