Phishing Campaigns Abusing MSP360 RMM for Persistent Access
Threat actors are distributing masqueraded MSP360 RMM installers via phishing to establish persistent access and deploy secondary ScreenConnect remote-access channels for post-compromise activity.
Since July 2026, threat actors have conducted phishing campaigns to deploy legitimate, digitally signed MSP360 RMM (v2.5.0.67) software. These campaigns utilize diverse social-engineering lures, including fake meeting invitations, PDF-themed documents, and software update prompts, directing users to download payloads from legitimate cloud-hosted services such as Amazon S3, GitLab, and Dropbox.
Once executed, the installer requests UAC elevation. Upon success, it establishes persistent access through Windows services and utilizes the RMM agent to silently install ConnectWise ScreenConnect. This creates a secondary, redundant remote-administration channel that allows attackers to blend in with legitimate IT operations. The established access is subsequently used to deploy additional tooling for credential harvesting and data collection. The use of trusted, legitimate RMM software significantly reduces detection opportunities as the activity mirrors standard administrative workflows. Organizations are advised to monitor for unauthorized or uncommon use of RMM binaries in their environments.
Attack Chain
- Phishing lures delivered via email direct victims to actor-controlled landing pages masquerading as collaboration or document portals.
- Victims download a masqueraded, digitally signed MSP360 RMM (v2.5.0.67) installer with a deceptive filename.
- The installer executes from the Downloads directory and drops helper components (System.dll, nsExec.dll, UAC.dll) to the local disk.
- The installer triggers a UAC elevation prompt to gain administrative privileges.
- Upon elevation, the installer registers 'RMM.Agent.exe' and 'RMM.Agent.Launcher.exe' as Windows services for persistent access.
- The RMM agent is instructed via the attacker to invoke PowerShell for downloading and silently installing a ConnectWise ScreenConnect client.
- The threat actor uses the redundant ScreenConnect remote-access channel to deploy post-exploitation tools.
- Final objectives, including credential access and information collection, are executed via the remote-management channels.
Impact
The abuse of legitimate RMM software allows actors to maintain long-term, persistent access to compromised endpoints. By creating redundant remote-access channels (MSP360 and ScreenConnect), attackers ensure continued visibility and control even if one channel is discovered or disabled. Successful compromises lead to sensitive data theft and credential harvesting, potentially escalating to broader network intrusion and lateral movement.
Recommendation
- Deploy the Sigma rules provided in this brief to detect the execution of MSP360 or ScreenConnect binaries originating from unusual locations or processes.
- Block or restrict the use of unauthorized RMM software; create an allowlist of approved RMM agents and monitor for any deviation in process paths or file hashes.
- Enable enhanced monitoring for 'eventcreate.exe' and PowerShell execution associated with service installation, as observed during the MSP360 setup process.
- Monitor DNS and proxy logs for connections to known RMM distribution hosting sites (S3, Dropbox, GitLab, etc.) when initiated by user-executed binaries from the Downloads folder.
Immediate actions
Block the identified SHA256 hash across all endpoints.
Threat Hunt
Search for instances of MSP360 or ScreenConnect services registered on endpoints not associated with IT administrative tasks.
Data: Endpoint service registry logs
Enrichment needed
- Infrastructure URLs (CTI) Further identification of specific attacker-controlled landing pages.
Mitigations
Implement application control policies to restrict unauthorized RMM installation.
T1219
Detection coverage 1
Detect Suspicious MSP360 RMM Installation
highDetects the execution of MSP360 RMM components that may indicate a malicious deployment from an untrusted source or location.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
1
hash_sha256
| Type | Value |
|---|---|
| hash_sha256 | 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc |