Executive Summary
Phishing campaigns in July 2026 distributed a masqueraded Microsoft MSP360 Remote Monitoring and Management (RMM) installer through social engineering lures, such as meeting invitations and PDF-themed content. Upon execution, the legitimate MSP360 installer established remote management access on affected devices. Threat actors then utilized this initial foothold to download and install the ConnectWise ScreenConnect client, creating a secondary remote-access channel. This process involved abusing legitimate administrative software to achieve persistence, enabling credential access, and deploying additional tooling for information collection.
The intrusion began with initial access via phishing, where victims downloaded installers disguised as legitimate documents or software updates from attacker-controlled cloud infrastructure. The installation routine leveraged User Account Control (UAC) elevation and installed MSP360 services, establishing persistence via both service registrations and registry autorun entries. Following this foothold, the RMM agent was used to execute PowerShell commands to download and install ScreenConnect, which provided a secondary remote access mechanism. Subsequently, threat actors utilized the established ScreenConnect session to transfer and execute files resembling legitimate system tools for credential access and data collection.
Separate activity was observed where FaronicsDeployAgent.exe was used similarly to MSP360 RMM to deploy ScreenConnect, indicating that other legitimate remote administration software could also be leveraged for initial access and subsequent remote access channel establishment.
Facts Only
* Phishing campaigns distributed a masqueraded MSP360 RMM installer (v2.5.0.67) using lures like meeting invitations, PDF themes, and software update prompts.
* The legitimate installer established remote management access upon execution of the malicious file.
* The installer dropped components like System.dll, nsExec.dll, and UAC.dll before relaunching with elevation workflows.
* The installer recorded installation status using eventcreate.exe, generating "Begin installation" and "End installation. MSP360 de Success." events from the MSP360 RMM Agent installer source.
* The installer registered Windows services (RMM.Agent.exe & RMM.Agent.Launcher.exe) for persistence.
* The installer created registry-based autorun entries for MSP360 user interface components.
* The installer modified the Windows Firewall by creating an inbound rule allowing UDP traffic to C:\Program Files\RMM Agent\RMM.Agent.exe on port 48678.
* The RMM agent service launched PowerShell, which executed Invoke-WebRequest to download and silently install a ConnectWise ScreenConnect MSI package.
* The installation deployed ScreenConnect components including ScreenConnect.ClientService.exe and ScreenConnect.WindowsClient.exe.
* Threat actors used the ScreenConnect session to transfer and execute files such as WindVerify.exe, WindowsUpdate.exe, Passwords.EXE, and HideMouseGUI.exe in directories like C:\Users\%user%\OneDrive\Documents\ScreenConnect\Temp\.
* FaronicsDeployAgent.exe was also observed being used similarly to MSP360 RMM for initial access followed by ScreenConnect installation.
Full Take
The narrative illustrates a sophisticated method of trust erosion: weaponizing the inherent administrative functionality of legitimate remote management tools to facilitate multi-stage compromise. The core pattern is the pivot from an Initial Access vector (phishing) to establishing deep, trusted persistence via RMM software, followed by escalating privileges and lateral movement through secondary remote access mechanisms like ScreenConnect. This exploitation is highly effective because it leverages existing organizational trust, allowing malicious activity to blend seamlessly within established IT operations—a hallmark of modern adversary behavior.
The reliance on legitimate installers for payload delivery (T1204) and subsequent use of the installed agent’s capabilities to deploy secondary access tools (T1105) highlights a strategic choice by threat actors: minimizing noise while maximizing access. The creation of file names mimicking benign software significantly reduces immediate scrutiny, fitting the pattern of evasion through semantic camouflage (T1036). Furthermore, the observation that distinct legitimate remote administration agents could be leveraged for this chaining demonstrates that the vulnerability is not specific to a single vendor tool but resides in the operational trust placed within remote management systems.
The implication for defense lies in moving beyond simple signature detection of known malware to focusing on behavioral anomalies within trusted processes. If an RMM agent or deployment utility initiates network downloads of unusual files, or subsequently spawns non-standard remote access tools, this sequence—RMM execution leading to remote session initiation—must be treated as a high-fidelity indicator of compromise, regardless of the initial software legitimacy. The focus must shift to auditing the legitimate function layers for unauthorized functional chaining and ensuring strict control over which systems are permitted to perform elevation and remote management actions within the environment.
Bridge Questions:
What internal processes currently exist to monitor and flag sequences where a legitimate RMM agent invokes PowerShell or system installation commands, especially when coupled with external network calls?
How can organizations differentiate between an approved MSP360 deployment and one that has been subverted by threat actors using similar operational commands and persistence mechanisms?
If other legitimate remote administration tools are being leveraged in this manner, what systemic controls can be implemented to enforce a unified security posture across all remote access technologies?
From the original · Microsoft Security Blog
In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.Read the full story at microsoft.com
Sentinel — Human
This text reads like a highly technical post-mortem report generated by security researchers or a vendor, characterized by precise detail and structured evidence presentation.
