{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/msp360-rmm-v2.5.0.67/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MSP360 RMM (v2.5.0.67)","ScreenConnect"],"_cs_severities":["high"],"_cs_tags":["phishing","rmm","persistence","remote-access"],"_cs_type":"advisory","_cs_vendors":["MSP360","ConnectWise"],"content_html":"\u003cp\u003eSince July 2026, threat actors have conducted phishing campaigns to deploy legitimate, digitally signed MSP360 RMM (v2.5.0.67) software. These campaigns utilize diverse social-engineering lures, including fake meeting invitations, PDF-themed documents, and software update prompts, directing users to download payloads from legitimate cloud-hosted services such as Amazon S3, GitLab, and Dropbox.\u003c/p\u003e\n\u003cp\u003eOnce executed, the installer requests UAC elevation. Upon success, it establishes persistent access through Windows services and utilizes the RMM agent to silently install ConnectWise ScreenConnect. This creates a secondary, redundant remote-administration channel that allows attackers to blend in with legitimate IT operations. The established access is subsequently used to deploy additional tooling for credential harvesting and data collection. The use of trusted, legitimate RMM software significantly reduces detection opportunities as the activity mirrors standard administrative workflows. Organizations are advised to monitor for unauthorized or uncommon use of RMM binaries in their environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePhishing lures delivered via email direct victims to actor-controlled landing pages masquerading as collaboration or document portals.\u003c/li\u003e\n\u003cli\u003eVictims download a masqueraded, digitally signed MSP360 RMM (v2.5.0.67) installer with a deceptive filename.\u003c/li\u003e\n\u003cli\u003eThe installer executes from the Downloads directory and drops helper components (System.dll, nsExec.dll, UAC.dll) to the local disk.\u003c/li\u003e\n\u003cli\u003eThe installer triggers a UAC elevation prompt to gain administrative privileges.\u003c/li\u003e\n\u003cli\u003eUpon elevation, the installer registers 'RMM.Agent.exe' and 'RMM.Agent.Launcher.exe' as Windows services for persistent access.\u003c/li\u003e\n\u003cli\u003eThe RMM agent is instructed via the attacker to invoke PowerShell for downloading and silently installing a ConnectWise ScreenConnect client.\u003c/li\u003e\n\u003cli\u003eThe threat actor uses the redundant ScreenConnect remote-access channel to deploy post-exploitation tools.\u003c/li\u003e\n\u003cli\u003eFinal objectives, including credential access and information collection, are executed via the remote-management channels.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe abuse of legitimate RMM software allows actors to maintain long-term, persistent access to compromised endpoints. By creating redundant remote-access channels (MSP360 and ScreenConnect), attackers ensure continued visibility and control even if one channel is discovered or disabled. Successful compromises lead to sensitive data theft and credential harvesting, potentially escalating to broader network intrusion and lateral movement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Sigma rules provided in this brief to detect the execution of MSP360 or ScreenConnect binaries originating from unusual locations or processes.\u003c/li\u003e\n\u003cli\u003eBlock or restrict the use of unauthorized RMM software; create an allowlist of approved RMM agents and monitor for any deviation in process paths or file hashes.\u003c/li\u003e\n\u003cli\u003eEnable enhanced monitoring for 'eventcreate.exe' and PowerShell execution associated with service installation, as observed during the MSP360 setup process.\u003c/li\u003e\n\u003cli\u003eMonitor DNS and proxy logs for connections to known RMM distribution hosting sites (S3, Dropbox, GitLab, etc.) when initiated by user-executed binaries from the Downloads folder.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T01:17:44Z","date_published":"2026-09-30T01:17:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-phishing-rmm-abuse/","summary":"Threat actors are distributing masqueraded MSP360 RMM installers via phishing to establish persistent access and deploy secondary ScreenConnect remote-access channels for post-compromise activity.","title":"Phishing Campaigns Abusing MSP360 RMM for Persistent Access","url":"https://feed.craftedsignal.io/briefs/2026-09-phishing-rmm-abuse/"}],"language":"en","title":"CraftedSignal Threat Feed - MSP360 RMM (V2.5.0.67)","version":"https://jsonfeed.org/version/1.1"}