Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access
Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) (TL-2026-2788) is a high-severity phishing campaign, first published 2026-09-29. It has no confirmed attribution, affects Microsoft Windows (endpoints where unapproved RMM software can be, maps to 17 MITRE ATT&CK techniques (T1005, T1036.005, T1059.001), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-2788
- Threat ID
- TL-2026-2788
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-29
- Last reviewed
- 2026-09-29
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- multiple industries
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 27
Malware and tooling in Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)
Malware and tooling: ConnectWise ScreenConnect, MSP360, MSP360 RMM, ScreenConnect
Microsoft Defender Experts observed phishing campaigns in July 2026 that deliver a masqueraded MSP360 RMM v2.5.0.67 installer, which is then used to silently deploy ConnectWise ScreenConnect for redundant remote access, credential theft and data collection. The activity is unattributed and targets organizations across multiple industries.
How Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) works
Microsoft Defender Experts identified phishing campaigns, active from July 2026, that distribute legitimate MSP360 remote monitoring and management (RMM) software masqueraded as something else. Lures include workplace meeting requests, Zoom and Google Meet installation prompts, Adobe Acrobat / PDF reader updates, RSVP invitations and e-cards, job offer documents, document review/signature requests and DHL package delivery content. Phishing emails point to actor-controlled landing pages that impersonate document portals, invitation workflows, Adobe Reader pages, Zoom installers and collaboration platforms. Victims are then redirected to download locations on attacker infrastructure and on legitimate cloud services (Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase). Observed installer file names follow a pattern of a themed lure name plus '_rmm_v2.5.0.67_oid<id>.exe', for example VIP_ECARD_INVITATION_rmm_v2.5.0.67, ZoomSetup_Installation_v2.5.0.67, 'PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67', RSVP_INVITATION_E_CARD_rmm_v2.5.0.67 and SSA.GOV_STATEMENT_rmm_v2.5.0.67.
The installer is an NSIS-style package that drops System.dll, nsExec.dll, UAC.dll, RMM.Agent.exe and RMM.Agent.Launcher.exe under C:\Program Files\RMM Agent\. RMM.Agent.exe and RMM.Agent.Launcher.exe are registered as Windows services, registry autorun entries are created for the MSP360 UI components, and an inbound firewall allow rule is created for RMM.Agent.exe on UDP port 48678. Microsoft's report names seven actor-associated domains used with the RMM agent (adswre.cfd, trews.cfd, adsaw.cfd, swedcorry.stefneyv.com, ojsuyw.niyari.org, bunstar.harej.si and sdfghj.rd-team.ru).
Once the MSP360 agent is running, the actor uses it to execute PowerShell that downloads ClientSetup.msi from actor infrastructure and installs ConnectWise ScreenConnect silently with msiexec.exe /qn, giving a second, redundant remote access channel (ScreenConnect.ClientService.exe and ScreenConnect.WindowsClient.exe). Through ScreenConnect the actor stages further tooling in ...\Documents\ScreenConnect\Temp\ (including under the OneDrive-redirected Documents folder). The transferred tools include fake Windows security/PIN/password prompt executables (WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, WindowsPassKey.exe, PIN.exe, Passwords.EXE), Phone Link themed executables, Defender control utilities (DefenderControl.exe, DefenderDT.exe), UI-hiding utilities (SCHider.exe, HideFromControlPanel.exe, BannerHider.exe, HideCursor.exe, HideMouse.exe, MouseHiderGUI.exe, HideUL.exe, HideMouseApp.dll) and NirSoft-style browser credential viewers (WebBrowserPassView.exe, WebBrowserBookmarksView.exe). The tooling is consistent with credential theft, browser data collection and concealment of the remote session from the user.
Because both MSP360 and ScreenConnect are legitimate, signed administration products, the activity blends with normal IT operations and may bypass controls that only look for malware. Microsoft has not attributed the activity to a named threat actor. Defenders should inventory approved RMM tools, enforce MFA on them, use application control (WDAC/AppLocker) to block unapproved RMM software, hunt for the listed hashes/paths/services, and reset credentials on any host with an unapproved RMM install.
MITRE ATT&CK techniques used in TL-2026-2788
Collection
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1218.007 Msiexec
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204 User Execution
Command and Control
T1071.001 Web Protocols; T1219 Remote Access Tools; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery
defense-impairment
Persistence
T1543.003 Windows Service; T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1555.003 Credentials from Web Browsers
Initial Access
Resource Development
Affected products and versions in Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)
- Microsoft — Windows (endpoints where unapproved RMM software can be installed)
- MSP360 — MSP360 RMM Agent (legitimate software abused, v2.5.0.67)
Vulnerable versions: 2.5.0.67 - ConnectWise — ScreenConnect (legitimate software abused)
Remediation for Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)
Immediate actions
- Search for unapproved RMM software (MSP360 RMM Agent, ScreenConnect) and remove it; reset credentials for users on affected devices
- Hunt for RMM.Agent.exe / RMM.Agent.Launcher.exe services, C:\Program Files\RMM Agent\ and ScreenConnect\Temp staging directories
- Block the published domains and file hashes at the proxy, DNS and EDR layers
Workarounds
- Restrict unauthorized software with Application Control for Windows (WDAC) and AppLocker
- Block specific signed applications using certificate indicators
Longer-term hardening
- Govern approved RMM tools and enforce MFA on them
- Enable cloud-delivered protection in Microsoft Defender Antivirus
- Deploy attack surface reduction rules (ransomware protection, PsExec/WMI process creation blocking)
- Train users to recognize meeting, document-signature, Adobe/Zoom update and package-delivery lures
Timeline of Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)
- Actor transfers credential-prompt, browser password viewer, Defender control and UI-hiding tools through ScreenConnect into ScreenConnect\Temp staging directories
- RMM.Agent.exe runs PowerShell to download ClientSetup.msi from actor infrastructure and installs ConnectWise ScreenConnect silently via msiexec /qn for redundant access
- Victim runs the themed *_rmm_v2.5.0.67_oid*.exe; MSP360 agent installs to C:\Program Files\RMM Agent\, registers services, autoruns and a UDP 48678 inbound firewall rule
- Phishing emails with meeting, Zoom/Google Meet, Adobe update, RSVP/e-card, job offer, document-signature and DHL themes link to actor-controlled landing pages and cloud-hosted downloads (S3, R2, Dropbox, GitLab, Supabase)
- Microsoft Defender Experts identify phishing campaigns (July 2026; exact day not published) distributing masqueraded MSP360 RMM v2.5.0.67 installers across multiple industries
- Microsoft Security Blog publishes 'Phishing abuses RMM tools for persistent access' with IOCs, detections, mitigations and advanced hunting queries; activity remains unattributed
Sources cited for Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect)
- Phishing Abuses RMM Tools for Persistent Access
- Fake Bank of America "Action Needed" Phishing Email Deposits ScreenConnect Instead
- Trojanized ScreenConnect Installers Evolve, Dropping Multiple RATs on a Single Machine
- PDF-Borne Living-Off-the-Land Attacks with RMM Abuse
- New Phishing Campaign Abuses ConnectWise ScreenConnect to Take Over Devices
- Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025
- MITRE ATT&CK T1219 Remote Access Software
More in phishing
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations
- Former US Air Force Members Odimegwu and Mogaji Sentenced Over Phishing-Driven BEC Fraud Ring Targeting 15+ Organizations
- AI-Enabled Social Engineering and Synthetic Media (Deepfakes) Undermining Identity Verification
- Fake American Express "non-compliance" card-lock phishing campaign targets Australians
- Phishing Sites Engineered to Deceive AI Agents via Hidden Machine-Readable Instructions (Indirect Prompt Injection)
Detection coverage for TL-2026-2788
As of 2026-09-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2788 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-2788
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.