Microsoft said its Defender Experts team observed phishing campaigns in July 2026 that distributed a masqueraded MSP360 Remote Monitoring and Management installer to organizations across multiple industries, using it to establish remote access on victim devices. According to Microsoft, attackers then used that foothold to install a ConnectWise ScreenConnect client as a second, redundant remote-access channel.
How the campaigns worked
Microsoft said phishing emails directed users to actor-controlled landing pages impersonating document-sharing portals, invitation workflows, Adobe Reader download pages, Zoom installation pages and business collaboration platforms. Victims were redirected to download locations on attacker-controlled infrastructure and on legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase.
The payload was a legitimate, digitally signed MSP360 RMM v2.5.0.67 installer carrying deceptive filenames, Microsoft said. Observed examples included VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe and ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe. Lure themes ranged from workplace meeting requests and job offer documents to DHL and package-delivery content.
Microsoft said analysis showed many downloaded samples ultimately contained the same MSP360 installer package despite appearing as different files, letting the actor rotate delivery infrastructure while reusing the payload.
Foothold and second remote-access channel
According to Microsoft, after a user ran the installer and User Account Control elevation succeeded, the software deployed MSP360 components to C:Program FilesRMM Agent, registered two Windows services (RMM.Agent.exe and RMM.Agent.Launcher.exe), created registry autorun entries for tray components and added an inbound Windows Firewall rule allowing UDP traffic to the agent on port 48678. Where elevation was denied or aborted, installation terminated before persistence was established.
Microsoft said the installed RMM.Agent.exe service then launched PowerShell, modified the session execution policy and used Invoke-WebRequest to download an MSI named ClientSetup.msi from actor-controlled infrastructure, which was installed silently via msiexec.exe with the /qn switch. That deployed a ConnectWise ScreenConnect client, including ScreenConnect.ClientService.exe and ScreenConnect.WindowsClient.exe.
Microsoft stressed it did not observe exploitation of ScreenConnect software itself; the actors abused legitimately obtained remote administration software.
Post-compromise tooling
Microsoft said the actor used ScreenConnect's built-in RunFile functionality to transfer and execute additional binaries staged under ScreenConnectTemp directories in users' Documents and OneDrive Documents folders. Observed filenames included WindowsSecurity_PIN.exe, DefenderControl.exe, WebBrowserPassView.exe, SCHider.exe and HideCursor.exe.
Several filenames were intentionally chosen to resemble legitimate Windows, Microsoft Defender, Phone Link and security components, Microsoft said, and several of the tools are commonly associated with credential access, information collection and efforts to reduce defender visibility.
Microsoft also reported separate July activity in which FaronicsDeployAgent.exe, a legitimate deployment and remote access application, was used in a similar way as the initial remote management platform before ScreenConnect was installed.
Attribution and detection
Microsoft said it has not attributed the activity to a named threat actor and tracks the campaigns as unattributed.
The company listed Defender coverage including the Microsoft Defender Antivirus detection SupportScam:Win32/RogueMSP.MU!MTB for delivery of the masqueraded MSP360 application, plus Defender for Endpoint alerts such as "Suspicious usage of remote management software" and "Uncommon remote access software". Microsoft published indicators of compromise, advanced hunting queries and mapped MITRE ATT&CK techniques, and noted the observed MSP360 sample was signed using a certificate that has since been revoked.
What to do
- Govern approved RMM tools: Microsoft recommends enforcing security settings on approved RMM systems where possible, including multi-factor authentication.
- Restrict unauthorized software using Application Control for Windows policies to block unapproved IT management tools, including listing publisher certificates as untrusted; AppLocker publisher rules can block non-approved signed RMM instances.
- Use Microsoft Defender for Endpoint's block certificate action to block specific signed applications.
- Hunt for unapproved RMM installations using the queries Microsoft published; if one is found, reset passwords for accounts used to install the RMM services, and investigate further if a system-level account was used.
- Turn on cloud-delivered protection in Microsoft Defender Antivirus or the equivalent antivirus product.
- Enable the attack surface reduction rules "Use advanced protection against ransomware" and blocking process creations originating from PsExec and WMI commands, noting Microsoft's warning about possible compatibility issues on some server systems.
Key facts and where they come from
- Microsoft Defender Experts observed the phishing campaigns in July 2026 across multiple industries.
In July 2026, Microsoft Defender Experts observed phishing campaigns targeting organizations across multiple industries that distributed a masqueraded MSP360 Remote Monitoring and Management (RMM) installer
- The payload was a legitimate, digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames.
phishing lures delivered a legitimate, digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames
- Microsoft did not observe exploitation of ScreenConnect software itself.
Microsoft did not observe exploitation of ScreenConnect software itself; rather, threat actors abused legitimately obtained remote administration software to establish and maintain access.
- ClientSetup.msi was downloaded via PowerShell and installed silently with msiexec /qn, deploying ScreenConnect.
The downloaded package was then installed silently through msiexec.exe using the /qn switch, eliminating visible user interaction.
- The installer registered two Windows services and added a firewall rule on UDP port 48678.
The rule allowed inbound UDP traffic to C:Program FilesRMM AgentRMM.Agent.exe on port 48678.
- Microsoft has not attributed the campaigns to a named threat actor.
Microsoft has not attributed this activity to a named threat actor. The campaigns are tracked as unattributed activity.
- Cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase were used to host payloads.
Cloud-hosted services used for payload distribution included Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.
- Separate July activity used FaronicsDeployAgent.exe in a similar way before installing ScreenConnect.
the threat actor leveraged FaronicsDeployAgent.exe as the initial remote management platform and subsequently used it to download and install ScreenConnect
