Full Report
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
Analysis Summary
# Tool/Technique: Dual-RMM Phishing (MSP360 & ScreenConnect)
## Overview
This attack involves the abuse of legitimate Remote Monitoring and Management (RMM) tools to establish a persistent and redundant foothold within a target environment. By deploying a legitimate, signed installer for MSP360 (formerly CloudBerry Lab) and subsequently using it to install ConnectWise ScreenConnect, threat actors can blend into normal administrative traffic and bypass traditional security controls.
## Technical Details
- **Type:** Attack Technique / Abuse of Legitimate Tools
- **Platform:** Windows
- **Capabilities:** Remote desktop access, file transfer, privileged command execution (PowerShell), persistence, and lateral movement.
- **First Seen:** Detected by Microsoft in July 2026.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- [T1566.001 - Phishing: Spearphishing Attachment]
- **[TA0003 - Persistence]**
- [T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder]
- [T1543.003 - Create or Modify System Process: Windows Service]
- **[TA0004 - Privilege Escalation]**
- [T1548.002 - Abuse Elevation Control Mechanism: Bypass User Account Control]
- **[TA0005 - Defense Evasion]**
- [T1218 - System Binary Proxy Execution]
- [T1562.004 - Impair Defenses: Disable or Modify System Firewall]
- **[TA0002 - Execution]**
- [T1059.001 - Command and Scripting Interpreter: PowerShell]
- **[TA0011 - Command and Control]**
- [T1219 - Remote Access Software]
## Functionality
### Core Capabilities
- **Initial Foothold:** Uses social engineering lures (PDFs, Zoom invites) to trick users into running a legitimate but renamed MSP360 installer.
- **Privilege Elevation:** Re-launches itself via the Windows UAC elevation workflow to gain administrative rights.
- **Redundant Access:** Deploys a second RMM tool (ScreenConnect) using the first tool (MSP360) to ensure access remains if one tool is detected or removed.
- **Firewall Modification:** Automatically configures Windows Firewall to allow inbound traffic on specific ports for remote management.
### Advanced Features
- **Stealth Execution:** Leverages PowerShell through the RMM agent to download and install secondary payloads without triggering standard "malware" signatures.
- **Living off the Land:** Uses legitimate administrative functions (like ScreenConnect's `RunFile`) to perform post-compromise actions.
## Indicators of Compromise
- **File Names:**
- `VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe`
- `ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe`
- `PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exe`
- `RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_oid[redacted].exe`
- `SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe`
- **Registry Keys:**
- Autorun entries for `MSP360` under standard Run/RunOnce keys.
- **Network Indicators:**
- Inbound UDP traffic on port `48678`.
- Connections to attacker-controlled buckets/repositories on:
- `s3[.]amazonaws[.]com`
- `cloudflare-r2[.]com`
- `dropbox[.]com`
- `gitlab[.]com`
- `supabase[.]co`
- **Behavioral Indicators:**
- Execution of `RMM.Agent.exe` or `RMM.Agent.Launcher.exe` from unexpected user directories.
- PowerShell commands initiated by RMM child processes to download `.exe` or `.msi` files.
- Spontaneous UAC prompts for RMM software not managed by the organization's IT department.
## Associated Threat Actors
- **Unknown:** The activity has not yet been attributed to a specific tracked group, though the sophistication suggests organized cybercriminal or espionage intent.
## Detection Methods
- **Behavioral Detection:** Monitor for the installation of RMM tools (MSP360, Faronics, ScreenConnect) that are not part of the official corporate software inventory.
- **Process Monitoring:** Audit `netsh advfirewall` commands that open ports for non-standard administrative applications.
- **Service Monitoring:** Alert on the creation of new Windows services named `RMM.Agent`.
- **Phishing Defense:** Scan email attachments for RMM installers renamed to mimic common document or meeting application file names.
## Mitigation Strategies
- **Software Restriction Policies:** Implement AppLocker or Windows Defender Application Control (WDAC) to block unauthorized RMM software.
- **Least Privilege:** Enforce standard user accounts to prevent automated UAC elevation by installers.
- **Network Segmentation:** Block known RMM-related domains and ports at the firewall level if those tools are not used by your IT department.
- **User Education:** Train employees to recognize social engineering lures, specifically those requesting the installation of software to view invitations or PDFs.
## Related Tools/Techniques
- **Faronics Deploy:** Also observed being used as an alternative initial entry RMM tool.
- **ConnectWise ScreenConnect:** The secondary "fail-safe" remote access tool.
- **AnyDesk/TeamViewer Abuse:** Similar techniques involving the abuse of legitimate remote access software for malicious persistence.