Microsoft (29 Sep): phishing deploys masqueraded MSP360 RMM → ScreenConnect second channel for persistence
Microsoft Security Research / Defender Experts (29 September 2026) document phishing campaigns observed from July 2026 that deliver a legitimate, digitally signed MSP360 Remote Monitoring and Management installer (v2.5.0.67) under deceptive filenames via meeting invites, PDF-themed lures, fake software-update prompts and related social engineering. After UAC elevation the installer establishes MSP360 services, then uses the RMM agent to download and silently install ConnectWise ScreenConnect as a second remote-administration channel for credential access and data collection. Microsoft did not observe exploitation of ScreenConnect itself — abuse of legitimately obtained admin software. THN (30 Sep) amplifies as US-focused “CSuite” phishing stealing Microsoft 365 sessions and deploying RMM tools (51% of 351 sandbox submissions from the US in that wire). Primary: Microsoft Security Blog; wire: The Hacker News 30 Sep.
- Product
- MSP360 RMM (abused installer) + ConnectWise ScreenConnect (secondary channel); Microsoft 365 / endpoint environments
- Versions
- Observed MSP360 RMM installer v2.5.0.67 under deceptive names (Microsoft report). Not a product CVE — living-off-the-land RMM abuse.
- Exploited in Australia?
- unknown
- Patch to
- Block/allow-list RMM installers (MSP360, ScreenConnect and peers) to approved IT channels; alert on unexpected RMM service installs and ScreenConnect clients; harden UAC and email/meeting-invite phishing controls; use Microsoft hunting guidance in the blog for Defender for Endpoint.
Primary: Microsoft Security Blog — Phishing abuses RMM tools for persistent access (29 Sep 2026) · Vendor: Microsoft Security Blog · The Hacker News — CSuite phishing / M365 sessions / RMM (30 Sep 2026)
