Dual RMM Phishing Attack Evades Defenses
Microsoft says phishing emails hid a legitimate MSP360 installer behind meeting and PDF lures, then used it to install ScreenConnect as a redundant remote-access channel.
The email looked like a meeting invitation or a PDF to review. What it carried was a digitally signed remote monitoring and management installer, packaged under a filename designed to blend into ordinary work. According to Microsoft, that installer gave attackers a first foothold on the endpoint, and from there they quietly added a second remote-access tool as a backup channel.
The activity, detected in July 2026, is not an exploit of a software flaw. It is the abuse of tools that IT departments use every day, which is exactly what makes it hard to separate from normal administration.
A legitimate installer as the first step
The Microsoft Security Research team described a phishing chain that distributes an installer for the MSP360 Remote Monitoring and Management software, wrapped in social-engineering themes including meeting invitations, PDF-themed lures, and software update prompts.
"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software," the Microsoft Security Research team said.
The installer itself is not malicious. It is a digitally signed MSP360 RMM v2.5.0.67 package, and that signature is part of why it can slip past defenses that rely on reputation and code-signing checks.
Filenames built to look routine
The campaign attaches or links to the installer under names that mix a plausible business document with the underlying RMM version string. Microsoft listed examples such as VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe, PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe, RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe, and SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe.
Those names are not random. They are chosen to match the kind of file a busy employee might open without a second thought, and they carry the version identifier of the legitimate product so the file appears consistent with a real software update.
Where the installers are staged
Microsoft said the installer packages are hosted on attacker-controlled infrastructure as well as legitimate cloud services, including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.
Using mainstream hosting and storage platforms gives the download a recognizable domain and a clean reputation. A victim who clicks a link is not connecting to an obviously suspicious server, and the file transfer can look like ordinary cloud activity to network monitoring tools.
Getting privileged, then staying put
Once the installer runs, it drops multiple DLLs and relaunches itself by invoking the Windows User Account Control elevation workflow to run in a privileged context. According to Microsoft, it then establishes persistent access by deploying MSP360 and uses the RMM tool to execute PowerShell for stealthily installing ScreenConnect.
The installer also enumerates installed .NET runtimes and registers two Windows services, RMM.Agent.exe and RMM.Agent.Launcher.exe. It creates Registry-based autorun entries so MSP360 launches automatically when a user signs in, and it modifies the Windows Firewall configuration to allow inbound UDP traffic to MSP360 on port 48678.
Each of those steps mirrors what a legitimate RMM deployment would do. That is the point: the services, the autorun entries, and the firewall rule are all consistent with an IT team rolling out remote management software.
The second RMM as a backup channel
With MSP360 in place, the attackers install a ConnectWise ScreenConnect client, giving them a redundant remote-access path to the compromised endpoint. Microsoft said the access is then abused to deliver additional tools and carry out information collection and credential-access operations. The payloads are run through ScreenConnect's native RunFile functionality.
"The combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion," Microsoft said.
Running two RMM tools side by side means that if one channel is blocked, removed, or stops working, the other can still be used. It also means the malicious traffic looks like the remote administration traffic that many networks already permit.
A second tool, the same approach
Microsoft said it also observed a separate set of attacks in July 2026 that switched MSP360 for Faronics Deploy Agent to find a way in, and then used it to download and install ScreenConnect.
The substitution is the notable detail. The delivery theme and the end goal stayed the same, but the RMM tool used for the initial foothold changed, suggesting the operators are not tied to a single product.
"This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities," Microsoft said.
The activity has not been attributed to any known threat actor or group.
What defenders are up against
The chain Microsoft described relies on trust rather than a software bug. A signed installer, a routine-looking filename, a mainstream cloud host, and a legitimate RMM service all reduce the signals that would normally flag an intrusion.
- The campaign distributed a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames.
- Microsoft detected the multi-stage intrusion chain in July 2026, with a separate set of attacks in the same month using Faronics Deploy Agent instead of MSP360.
- The installer registers two Windows services, RMM.Agent.exe and RMM.Agent.Launcher.exe, and opens inbound UDP traffic on port 48678.
- Installers were staged on Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase, among other locations.
Because the tooling is legitimate, detection often depends on context: whether an RMM agent was expected on that endpoint, whether the user or IT team authorized it, and whether the surrounding behavior fits the organization's normal patterns.
Why the dual-RMM pattern matters
For businesses, the practical consequence is that an endpoint running a remote management agent is not automatically a clean endpoint. The same services and firewall rules that let administrators work remotely can let an intruder work remotely too, and a second RMM client makes that access harder to shut down with a single action.
For defenders, the story suggests that response plans built around blocking one remote-access tool may not be enough when a second channel is already installed. This is not a flaw in MSP360 or ScreenConnect, and Microsoft has not attributed the activity to a known group. But it does show that trusted administrative software can serve as both the way in and the way to stay in.
Readers who want the vendor's full technical description can find it in Microsoft's write-up, which covers the stages, the services created, and the network changes made on affected devices.
Sources
- The Hacker News Original source
- said Also reporting
- RMM.Agent.exe Also reporting
Continue Reading
Fortinet Zero-Day Hits FortiMail Gateways
Fortinet reports active exploitation of a critical FortiMail flaw, with patches still pending and CISA ordering federal fixes by October 4th.
DIVD breach linked to agentic AI attack
Dutch bug-hunting nonprofit says AI agents exploited Zammad zero-days, stealing researcher emails in seconds.
China-Linked Group Poses as AI Policy Experts
Proofpoint says TA419 has impersonated AI policy figures and economists since at least April 2025 to steal credentials from US think tank staff.