Attackers are leaning on legitimate remote management software to slip past defenses. In July 2026, Microsoft Defender Experts tracked phishing campaigns hitting organizations in multiple industries with a disguised MSP360 Remote Monitoring and Management (RMM) installer, spread through meeting invitations, PDF-themed lures, software update prompts, and other social-engineering bait.
The genuine MSP360 RMM software gave attackers a foothold, which they then used to install a ConnectWise ScreenConnect client as a redundant access channel. Microsoft found no exploitation of ScreenConnect itself. The actors simply abused legitimately obtained admin tools, then carried out information collection and credential theft while blending into routine IT activity.
How the MSP360 RMM Lures Worked
Emails led victims to attacker-run pages posing as document-sharing portals, invitation workflows, Adobe Reader and Zoom download pages, and collaboration platforms. Downloads came from attacker domains, likely compromised sites, and cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase, letting the actor rotate infrastructure quickly.
Themes ranged from meeting requests, Zoom and Google Meet installs, and Adobe Acrobat updates to RSVP e-cards, job offers, signature requests, and DHL delivery notices. Files such as VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe, PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exe, RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_oid[redacted].exe, and SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe often hid the same signed MSP360 RMM v2.5.0.67 package (SHA256: 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc; SHA1: f34330d4c6e0aa978dc3af40360c14b31ad51127).
Inside the MSP360 RMM Installation
Launched from the Downloads folder, the installer dropped System.dll, nsExec.dll, and UAC.dll, then requested User Account Control (UAC) elevation. When elevation was denied, setup stopped with no services or persistence created. When approved, it logged “Begin installation” and “End installation. MSP360 de Success.” through eventcreate.exe under the source “MSP360 RMM Agent installer” and placed components in C:\Program Files\RMM Agent.
It checked .NET runtimes with dotnet –list-runtimes, stopped any existing MSP360 services and registered two new ones, RMM.Agent.exe and RMM.Agent.Launcher.exe. Registry autorun entries launched tray apps at sign-in, and a firewall rule allowed inbound UDP traffic to RMM.Agent.exe on port 48678.
From the RMM Agent to ScreenConnect
The RMM.Agent.exe service then spawned PowerShell, changed the session’s execution policy and used Invoke-WebRequest to fetch ClientSetup.msi from actor infrastructure. Msiexec.exe installed it silently with the /qn switch, adding ScreenConnect.ClientService.exe, ScreenConnect.WindowsClient.exe, service registrations, uninstall entries, and authentication-related registry changes. The client contacted attacker servers, opening a channel independent of MSP360.
Using ScreenConnect’s RunFile feature, the actor staged and ran tools in C:\Users%user%\OneDrive\Documents\ScreenConnect\Temp\ and C:\Users%user%\Documents\ScreenConnect\Temp: WindVerify.exe, WindowsUpdate.exe, WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, WindowsPassKey.exe, SCHider.exe, PIN.exe, phonepc.exe, DefenderDT.exe, DefenderControl.exe, phonelinkupdate.exe, PhoneLinkPrompt.exe, Passwords.EXE, OpenCamera.exe, open_phone_link.exe, MouseHiderGUI.exe, HideUL.exe, HideMouseApp.dll, HideMouse.exe, HideFromControlPanel.exe, HideCursor.exe, BannerHider.exe, WebBrowserBookmarksView.exe and WebBrowserPassView.exe.
Many mimicked Windows, Defender, Phone Link, or security components and supported credential access, data collection, further payloads, and reduced defender visibility.
In a separate July activity, FaronicsDeployAgent.exe filled the same role as MSP360 RMM, downloading and installing ScreenConnect. Microsoft has not attributed either campaign to a named threat actor.
Reducing RMM Abuse Risk
Microsoft recommends enforcing multi-factor authentication on approved RMM tools and blocking unapproved ones with Application Control for Windows, which can mark certificates as untrusted, or AppLocker publisher rules. Defender for Endpoint’s block certificate action can stop specific signed applications.
Teams should hunt for unapproved RMM installs, reset passwords for accounts used to install them and investigate further if a system-level account was involved. Other steps include cloud-delivered protection in Microsoft Defender Antivirus and attack surface reduction rules for advanced ransomware protection and blocking process creation from PsExec and WMI commands, which may cause compatibility issues on some servers.






































