Microsoft Security researchers have documented phishing campaigns that disguised legitimate MSP360 Remote Monitoring and Management installers as meeting invitations, PDF tools, software updates and other familiar files. Once a recipient ran the signed installer, the attackers gained an initial remote-management foothold on the Windows device.
Two legitimate tools created redundant access
Microsoft said the MSP360 deployment was then used to download and install ConnectWise ScreenConnect, giving the operators a second remote-access channel. The researchers did not report exploitation of either product. Instead, the campaign relied on deceptive delivery and abuse of legitimately obtained administration software.
The observed activity began in July 2026 and used attacker-controlled infrastructure alongside services such as Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase. Post-compromise activity included information collection, credential access and delivery of additional tools.
RMM allowlists require behavioral monitoring
Defenders should inventory approved remote-management agents, alert on unusual installers and investigate one RMM product launching scripts that install another. Signed software and familiar cloud hosting do not make an execution chain trustworthy. Teams can follow related endpoint and identity risks in SectechMedia’s cyber-physical security coverage.

Leave a Reply