Cybersecurity

Microsoft: Phishing Campaigns Exploit Remote Management Tools to Establish Persistent Access to Devices

Microsoft observed phishing campaigns that distributed a legitimate MSP360 installer under deceptive names, then used it to install ConnectWise ScreenConnect and create two recurring remote-access channels. The company did not observe exploitation of a vulnerability in ScreenConnect; rather, the attackers abused trusted administrative tools to conduct subsequent activities, including information gathering and credential access.

2026-09-29
4 min read
8 views
certi.news Editorial Team
Microsoft: Phishing Campaigns Exploit Remote Management Tools to Establish Persistent Access to Devices

In July 2026, Microsoft observed phishing campaigns targeting organizations in multiple sectors. The campaigns distributed a legitimate installer for MSP360 Remote Monitoring and Management, version 2.5.0.67, under filenames suggesting meeting invitations, PDF documents, or familiar installation and update tools. After the file was executed and successfully elevated privileges through UAC, the attackers installed MSP360 services on the affected devices and used them to silently download and install the ConnectWise ScreenConnect client.

This created a second channel for remote access to the device, independent of the MSP360 channel, providing the attackers with persistent backup access and a means of transferring and executing additional files and tools. Microsoft confirmed that it did not observe exploitation of ScreenConnect itself; the core of the activity was the abuse of remote-management software that the attackers had legitimately obtained, making the operations appear more like routine IT administration and reducing the likelihood of detection.

How did the intrusion chain begin?

Users were led to pages impersonating document-sharing portals, meeting invitations, or Zoom and Adobe Reader installation pages. They were then directed to files hosted on infrastructure controlled by the attackers or on legitimate cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Despite differences in filenames and the stories used, analysis of the samples showed that many of them contained the same MSP360 package.

The lures included business-meeting requests, Zoom and Google Meet installations, Adobe Acrobat updates and PDF readers, RSVP invitations, job offers, requests to review and sign documents, as well as messages concerning DHL shipments. The campaign used a distribution infrastructure that could be rapidly switched, changing domains and filenames while retaining the same payload.

What happened after installation?

The installer created the RMM.Agent.exe and RMM.Agent.Launcher.exe services to maintain access and added automatic-start entries to the Windows Registry. It also modified the firewall to allow incoming UDP traffic to the MSP360 agent on port 48678. The MSP360 agent then launched PowerShell to download and silently install ClientSetup.msi using msiexec.exe /qn, resulting in the deployment of ScreenConnect components.

The subsequent ScreenConnect session was used to transfer and execute tools with names resembling Windows, Microsoft Defender, and Phone Link components, including tools associated with credential access, information gathering, and reducing the visibility of activity to defenders. Microsoft also observed similar activity in which FaronicsDeployAgent.exe was used as an initial gateway before ScreenConnect was installed.

Why does this matter?

The significance of this activity lies in the fact that it does not necessarily rely on clearly malicious software or the exploitation of a new vulnerability. Instead, it turns the management tools required by IT teams into access channels for attackers. The presence of a legitimate digital signature or a well-known program does not prove that its use within the organization is authorized, particularly when it arrives through phishing email or runs from an unusual download path.

Microsoft recommends restricting approved RMM tools and enabling multifactor authentication wherever possible; using Application Control for Windows or AppLocker to block unauthorized tools; and searching for unknown MSP360 and ScreenConnect installations. It also recommends reviewing the accounts used to install the services and resetting their passwords when an unauthorized installation is detected, in addition to enabling cloud-based protection and appropriate attack-surface-reduction rules.

Microsoft attributes the activity to an unknown entity and did not attribute it to a specific threat group. The company provides Advanced Hunting queries to search for the MSP360 fingerprint, PowerShell execution from RMM.Agent.exe, ScreenConnect connections, and files transferred through the RunFile function.

News source
Microsoft Security Blog
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news