Full Report
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.
Analysis Summary
# Tool/Technique: Abusing RMM for Persistent Access (MSP360 & ScreenConnect)
## Overview
This technique involves the abuse of legitimate Remote Monitoring and Management (RMM) software to establish initial access and maintain persistence within a target network. By using digitally signed, trusted administrative tools, threat actors can blend into normal IT operations and bypass security controls that might otherwise flag custom malware. In this campaign, MSP360 RMM was used as a primary foothold to deploy ConnectWise ScreenConnect as a redundant access channel.
## Technical Details
- **Type:** Technique (Living-off-the-Land / Tool Abuse)
- **Platform:** Windows
- **Capabilities:** Remote command execution, file transfer, persistent remote desktop access, and administrative control.
- **First Seen:** July 2026 (Reported by Microsoft Defender Experts)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link
- **TA0003 - Persistence**
- T1133 - External Remote Services
- **TA0005 - Defense Evasion**
- T1204.002 - User Execution: Malicious File
- T1553.002 - Subvert Trust Controls: Code Signing (Abuse of legitimate signed installers)
- **TA0002 - Execution**
- T1059.001 - Command and Scripting Interpreter: PowerShell
## Functionality
### Core Capabilities
- **Legitimate Installation:** Uses a signed MSP360 RMM v2.5.0.67 installer to avoid signature-based detection.
- **Persistence:** Establishes system services that ensure remote access survives reboots.
- **Remote Execution:** Leverages the RMM agent's native ability to invoke PowerShell commands with elevated privileges.
### Advanced Features
- **Redundant Access:** The primary RMM tool (MSP360) is used to silently download and install a second RMM tool (ConnectWise ScreenConnect) to ensure continued access if one channel is discovered and removed.
- **Social Engineering Lures:** Distributed via sophisticated masquerading, including fake Zoom/Google Meet installers, Adobe updates, and job offer documents.
## Indicators of Compromise
- **File Hashes:**
- **MSP360 Installer (SHA256):** `108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc`
- **MSP360 Installer (SHA1):** `f34330d4c6e0aa978dc3af40360c14b31ad51127`
- **File Names:** `Zoom_Setup.exe`, `Adobe_Reader_Update.exe`, `Meeting_Invite.exe`, `Job_Offer.pdf.exe` (Commonly masqueraded).
- **Network Indicators:**
- `s3.amazonaws[.]com` (Abused for hosting)
- `cloudflare-r2[.]com` (Abused for hosting)
- `dropbox[.]com`, `gitlab[.]com`, `supabase[.]co` (Abused for delivery)
- **Behavioral Indicators:**
- Execution of RMM installers from `Downloads` or `Temp` folders.
- PowerShell spawning from legitimate RMM processes (e.g., `RemoteManagement.exe`).
- Sudden installation of ScreenConnect shortly after an MSP360 installation.
## Associated Threat Actors
- While the specific actor is not named in this report, the TTPs are consistent with financially motivated groups (e.g., IABs or Ransomware affiliates) who specialize in maintaining persistent footholds via legitimate software.
## Detection Methods
- **Behavioral Detection:** Monitor for "Living-off-the-Land" activity where RMM agents initiate PowerShell to download external executables or scripts.
- **Process Monitoring:** Alert on the execution of unapproved RMM software installers across the environment, especially those signed by MSP360 or ConnectWise if not standard for the org.
- **Inventory Discrepancy:** Compare installed software lists against authorized IT asset registers to identify unauthorized RMM deployments.
## Mitigation Strategies
- **Software Restriction Policies:** Implement AppLocker or Windows Defender Application Control (WDAC) to block unauthorized RMM binaries.
- **Credential Protection:** Enforce Multi-Factor Authentication (MFA) on all remote access portals.
- **Endpoint Hardening:** Restrict User Account Control (UAC) to require administrative passwords for installations.
- **Network Filtering:** Block known file-hosting and code-repository domains if they are not required for business operations.
## Related Tools/Techniques
- **AnyDesk / TeamViewer Abuse:** Similar abuse of legitimate remote desktop software.
- **Living-off-the-Land Binaries (LoLBins):** Using trusted system tools to perform malicious actions.