Security & privacy

Attackers abuse MSP360 and ScreenConnect in dual-RMM phishing campaigns

Microsoft reports phishing campaigns using legitimate MSP360 installers to establish remote access, then deploying ScreenConnect for redundant control and data theft.

Secure File Share preview

Microsoft has identified a series of phishing campaigns that leverage legitimate Remote Monitoring and Management (RMM) software to compromise Windows endpoints. Detected in July 2026, these attacks use deceptive emails to distribute signed installers for MSP360, which attackers then use to install ConnectWise ScreenConnect for persistent, redundant remote access.

What happened

The intrusion chain begins with social engineering lures disguised as meeting invitations, PDF readers, or software updates. These emails contain links to digitally signed MSP360 RMM v2.5.0.67 installers hosted on attacker-controlled infrastructure or legitimate cloud services like Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. The file names are crafted to appear benign, such as VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe or ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe.

Once a user executes the installer, it drops multiple DLLs and invokes the Windows User Account Control (UAC) elevation workflow to gain privileged access. The malware establishes persistence by registering two Windows services, RMM.Agent.exe and RMM.Agent.Launcher.exe, and creating Registry-based autorun entries. It also modifies the Windows Firewall to allow inbound UDP traffic on port 48678 for the MSP360 agent. With this initial foothold established, the attacker uses PowerShell to stealthily download and install a ConnectWise ScreenConnect client.

This dual-RMM strategy provides attackers with redundant remote-access channels. If one tool is detected or removed, the other remains active. Microsoft noted that threat actors also tested this technique using Faronics Deploy Agent instead of MSP360, indicating a flexible approach to abusing trusted administrative software. The activity has not been attributed to any specific threat group.

Key details

  • Initial vector: Phishing emails with links to signed MSP360 RMM v2.5.0.67 installers hosted on cloud services.
  • Deceptive filenames: Installers use names mimicking legitimate software, such as Adobe Acrobat or Zoom setup files.
  • Persistence mechanisms: The malware registers Windows services and Registry autorun entries to survive reboots.
  • Firewall modification: Inbound UDP traffic on port 48678 is allowed to facilitate MSP360 communication.
  • Secondary payload: ScreenConnect is installed via PowerShell to provide a redundant remote access channel.
  • Alternative tools: Attackers also tested Faronics Deploy Agent as an initial foothold before installing ScreenConnect.

Background

Remote Monitoring and Management (RMM) tools are essential for IT teams to manage devices, deploy updates, and troubleshoot issues remotely. Because these tools require high-level privileges and network access, they are attractive targets for attackers. Legitimate RMM software is often digitally signed and whitelisted by security solutions, making it difficult to distinguish from malicious activity when abused.

ScreenConnect, now part of ConnectWise, is a popular remote support and access solution. By installing both MSP360 and ScreenConnect, attackers create a resilient command-and-control infrastructure. This "dual-RMM" approach allows them to blend malicious traffic with normal administrative workflows, reducing the likelihood of detection by standard security monitoring tools that may trust these applications.

Why it matters

For teams that manage their own infrastructure, this attack highlights the risk of trusting signed binaries and legitimate software alone. Traditional antivirus solutions may not flag MSP360 or ScreenConnect as malicious because they are valid, signed applications. This creates a blind spot where attackers can operate within the bounds of trusted software, making detection reliant on behavioral analysis rather than signature matching.

The use of cloud storage services like Amazon S3 and Dropbox to host payloads further complicates defense. Blocking these domains entirely is often impractical for businesses that rely on them for legitimate operations. Instead, security teams must focus on monitoring for unusual installation patterns, such as RMM tools being installed via user-initiated downloads rather than centralized management consoles.

Additionally, the redundancy provided by dual-RMM setups means that incident response becomes more complex. Removing one tool does not guarantee the attacker is locked out. Teams must audit all remote access software on their endpoints and ensure that only authorized instances are running. Failure to do so can lead to prolonged unauthorized access, data exfiltration, and credential theft.

What you can do

  • Audit installed RMM tools: Regularly scan endpoints for unauthorized instances of MSP360, ScreenConnect, or other remote access software.
  • Restrict installer execution: Use application control policies to prevent users from running unsigned or unexpected executables, even if they are digitally signed by known vendors.
  • Monitor firewall changes: Alert on modifications to Windows Firewall rules, particularly those opening UDP ports for unknown applications.
  • Verify cloud downloads: Investigate downloads from cloud storage services like S3 or Dropbox that result in executable files, especially if initiated via email links.
  • Disable unused services: Ensure that RMM agents are disabled or uninstalled on devices that do not require remote management.
  • Educate users: Train staff to recognize phishing lures that mimic software updates or meeting invitations, emphasizing the danger of clicking unknown links.

More news

All news