<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MSP360 RMM (V2.5.0.67) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/msp360-rmm-v2.5.0.67/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 01:17:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/msp360-rmm-v2.5.0.67/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Phishing Campaigns Abusing MSP360 RMM for Persistent Access</title><link>https://feed.craftedsignal.io/briefs/2026-09-phishing-rmm-abuse/</link><pubDate>Wed, 30 Sep 2026 01:17:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-phishing-rmm-abuse/</guid><description>Threat actors are distributing masqueraded MSP360 RMM installers via phishing to establish persistent access and deploy secondary ScreenConnect remote-access channels for post-compromise activity.</description><content:encoded><![CDATA[<p>Since July 2026, threat actors have conducted phishing campaigns to deploy legitimate, digitally signed MSP360 RMM (v2.5.0.67) software. These campaigns utilize diverse social-engineering lures, including fake meeting invitations, PDF-themed documents, and software update prompts, directing users to download payloads from legitimate cloud-hosted services such as Amazon S3, GitLab, and Dropbox.</p>
<p>Once executed, the installer requests UAC elevation. Upon success, it establishes persistent access through Windows services and utilizes the RMM agent to silently install ConnectWise ScreenConnect. This creates a secondary, redundant remote-administration channel that allows attackers to blend in with legitimate IT operations. The established access is subsequently used to deploy additional tooling for credential harvesting and data collection. The use of trusted, legitimate RMM software significantly reduces detection opportunities as the activity mirrors standard administrative workflows. Organizations are advised to monitor for unauthorized or uncommon use of RMM binaries in their environments.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Phishing lures delivered via email direct victims to actor-controlled landing pages masquerading as collaboration or document portals.</li>
<li>Victims download a masqueraded, digitally signed MSP360 RMM (v2.5.0.67) installer with a deceptive filename.</li>
<li>The installer executes from the Downloads directory and drops helper components (System.dll, nsExec.dll, UAC.dll) to the local disk.</li>
<li>The installer triggers a UAC elevation prompt to gain administrative privileges.</li>
<li>Upon elevation, the installer registers 'RMM.Agent.exe' and 'RMM.Agent.Launcher.exe' as Windows services for persistent access.</li>
<li>The RMM agent is instructed via the attacker to invoke PowerShell for downloading and silently installing a ConnectWise ScreenConnect client.</li>
<li>The threat actor uses the redundant ScreenConnect remote-access channel to deploy post-exploitation tools.</li>
<li>Final objectives, including credential access and information collection, are executed via the remote-management channels.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>The abuse of legitimate RMM software allows actors to maintain long-term, persistent access to compromised endpoints. By creating redundant remote-access channels (MSP360 and ScreenConnect), attackers ensure continued visibility and control even if one channel is discovered or disabled. Successful compromises lead to sensitive data theft and credential harvesting, potentially escalating to broader network intrusion and lateral movement.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Deploy the Sigma rules provided in this brief to detect the execution of MSP360 or ScreenConnect binaries originating from unusual locations or processes.</li>
<li>Block or restrict the use of unauthorized RMM software; create an allowlist of approved RMM agents and monitor for any deviation in process paths or file hashes.</li>
<li>Enable enhanced monitoring for 'eventcreate.exe' and PowerShell execution associated with service installation, as observed during the MSP360 setup process.</li>
<li>Monitor DNS and proxy logs for connections to known RMM distribution hosting sites (S3, Dropbox, GitLab, etc.) when initiated by user-executed binaries from the Downloads folder.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>phishing</category><category>rmm</category><category>persistence</category><category>remote-access</category></item></channel></rss>