Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access

Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) (TL-2026-2788) is a high-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Windows (endpoints where unapproved RMM software can be, maps to 17 MITRE ATT&CK techniques (T1005, T1036.005, T1059.001), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-2788

Threat ID
TL-2026-2788
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-29
Last reviewed
2026-09-29
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
multiple industries
Target regions
Global
Detection rules
9
Indicators of compromise
27

Malware and tooling in Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)

Malware and tooling: ConnectWise ScreenConnect, MSP360, MSP360 RMM, ScreenConnect

Microsoft Defender Experts observed phishing campaigns in July 2026 that deliver a masqueraded MSP360 RMM v2.5.0.67 installer, which is then used to silently deploy ConnectWise ScreenConnect for redundant remote access, credential theft and data collection. The activity is unattributed and targets organizations across multiple industries.

How Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) works

Microsoft Defender Experts identified phishing campaigns, active from July 2026, that distribute legitimate MSP360 remote monitoring and management (RMM) software masqueraded as something else. Lures include workplace meeting requests, Zoom and Google Meet installation prompts, Adobe Acrobat / PDF reader updates, RSVP invitations and e-cards, job offer documents, document review/signature requests and DHL package delivery content. Phishing emails point to actor-controlled landing pages that impersonate document portals, invitation workflows, Adobe Reader pages, Zoom installers and collaboration platforms. Victims are then redirected to download locations on attacker infrastructure and on legitimate cloud services (Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase). Observed installer file names follow a pattern of a themed lure name plus '_rmm_v2.5.0.67_oid<id>.exe', for example VIP_ECARD_INVITATION_rmm_v2.5.0.67, ZoomSetup_Installation_v2.5.0.67, 'PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67', RSVP_INVITATION_E_CARD_rmm_v2.5.0.67 and SSA.GOV_STATEMENT_rmm_v2.5.0.67.

The installer is an NSIS-style package that drops System.dll, nsExec.dll, UAC.dll, RMM.Agent.exe and RMM.Agent.Launcher.exe under C:\Program Files\RMM Agent\. RMM.Agent.exe and RMM.Agent.Launcher.exe are registered as Windows services, registry autorun entries are created for the MSP360 UI components, and an inbound firewall allow rule is created for RMM.Agent.exe on UDP port 48678. Microsoft's report names seven actor-associated domains used with the RMM agent (adswre.cfd, trews.cfd, adsaw.cfd, swedcorry.stefneyv.com, ojsuyw.niyari.org, bunstar.harej.si and sdfghj.rd-team.ru).

Once the MSP360 agent is running, the actor uses it to execute PowerShell that downloads ClientSetup.msi from actor infrastructure and installs ConnectWise ScreenConnect silently with msiexec.exe /qn, giving a second, redundant remote access channel (ScreenConnect.ClientService.exe and ScreenConnect.WindowsClient.exe). Through ScreenConnect the actor stages further tooling in ...\Documents\ScreenConnect\Temp\ (including under the OneDrive-redirected Documents folder). The transferred tools include fake Windows security/PIN/password prompt executables (WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, WindowsPassKey.exe, PIN.exe, Passwords.EXE), Phone Link themed executables, Defender control utilities (DefenderControl.exe, DefenderDT.exe), UI-hiding utilities (SCHider.exe, HideFromControlPanel.exe, BannerHider.exe, HideCursor.exe, HideMouse.exe, MouseHiderGUI.exe, HideUL.exe, HideMouseApp.dll) and NirSoft-style browser credential viewers (WebBrowserPassView.exe, WebBrowserBookmarksView.exe). The tooling is consistent with credential theft, browser data collection and concealment of the remote session from the user.

Because both MSP360 and ScreenConnect are legitimate, signed administration products, the activity blends with normal IT operations and may bypass controls that only look for malware. Microsoft has not attributed the activity to a named threat actor. Defenders should inventory approved RMM tools, enforce MFA on them, use application control (WDAC/AppLocker) to block unapproved RMM software, hunt for the listed hashes/paths/services, and reset credentials on any host with an unapproved RMM install.

MITRE ATT&CK techniques used in TL-2026-2788

Collection

T1005 Data from Local System

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1218.007 Msiexec

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204 User Execution

Command and Control

T1071.001 Web Protocols; T1219 Remote Access Tools; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery

defense-impairment

T1112 Modify Registry

Persistence

T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder

Credential Access

T1555.003 Credentials from Web Browsers

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1583.006 Web Services

Affected products and versions in Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)

  • Microsoft — Windows (endpoints where unapproved RMM software can be installed)
  • MSP360 — MSP360 RMM Agent (legitimate software abused, v2.5.0.67)
    Vulnerable versions: 2.5.0.67
  • ConnectWise — ScreenConnect (legitimate software abused)

Remediation for Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)

Immediate actions

  • Search for unapproved RMM software (MSP360 RMM Agent, ScreenConnect) and remove it; reset credentials for users on affected devices
  • Hunt for RMM.Agent.exe / RMM.Agent.Launcher.exe services, C:\Program Files\RMM Agent\ and ScreenConnect\Temp staging directories
  • Block the published domains and file hashes at the proxy, DNS and EDR layers

Workarounds

  • Restrict unauthorized software with Application Control for Windows (WDAC) and AppLocker
  • Block specific signed applications using certificate indicators

Longer-term hardening

  • Govern approved RMM tools and enforce MFA on them
  • Enable cloud-delivered protection in Microsoft Defender Antivirus
  • Deploy attack surface reduction rules (ransomware protection, PsExec/WMI process creation blocking)
  • Train users to recognize meeting, document-signature, Adobe/Zoom update and package-delivery lures

Timeline of Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)

  • Actor transfers credential-prompt, browser password viewer, Defender control and UI-hiding tools through ScreenConnect into ScreenConnect\Temp staging directories
  • RMM.Agent.exe runs PowerShell to download ClientSetup.msi from actor infrastructure and installs ConnectWise ScreenConnect silently via msiexec /qn for redundant access
  • Victim runs the themed *_rmm_v2.5.0.67_oid*.exe; MSP360 agent installs to C:\Program Files\RMM Agent\, registers services, autoruns and a UDP 48678 inbound firewall rule
  • Phishing emails with meeting, Zoom/Google Meet, Adobe update, RSVP/e-card, job offer, document-signature and DHL themes link to actor-controlled landing pages and cloud-hosted downloads (S3, R2, Dropbox, GitLab, Supabase)
  • Microsoft Defender Experts identify phishing campaigns (July 2026; exact day not published) distributing masqueraded MSP360 RMM v2.5.0.67 installers across multiple industries
  • Microsoft Security Blog publishes 'Phishing abuses RMM tools for persistent access' with IOCs, detections, mitigations and advanced hunting queries; activity remains unattributed

Sources cited for Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)

More in phishing

Detection coverage for TL-2026-2788

As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2788 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2788

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats