Fake invites that install MSP360, then ScreenConnect
Phishing delivers a signed MSP360 RMM agent that silently adds ConnectWise ScreenConnect as a backup channel. How it works, what to hunt and how to clean up.
By Yaali. October 7, 2026, 5 min read, Phishing, Threat intel, Windows.
On September 29, Microsoft Defender Experts published a report on phishing campaigns that hand victims a legitimate, digitally signed installer for MSP360's remote monitoring and management (RMM) agent, version 2.5.0.67, renamed to look like a meeting invitation, a Zoom setup file or a PDF reader. Once installed, the agent is used to download and silently install ConnectWise ScreenConnect, a second remote access tool. The campaigns ran in July 2026 against organizations in multiple industries; the report came out two months later, so treat this as a hunt across July to today, not only a fresh alert.
No vulnerability in MSP360 or ScreenConnect is involved. Both are normal IT products, signed by their publishers and used daily by managed service providers, which is why they slip past email filters and antivirus that look for malware. Any Windows estate where users can run downloaded executables is in scope, and an attacker who keeps two independent remote access tools on a machine survives the usual fix of uninstalling the one you find.

How it works
The lures cover meeting requests, Zoom and Google Meet install prompts, Adobe Acrobat updates, RSVP invitations and e-cards, job offers, signature requests and DHL delivery notices. Links lead to attacker landing pages dressed as document portals or download pages, with the payload stored on Amazon S3, Cloudflare R2, Dropbox, GitLab or Supabase. Filenames Microsoft lists include VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe and SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe. The rmm_v2.5.0.67 fragment left in the names is a cheap thing to search mail and proxy logs for.
The installer triggers a User Account Control (UAC) prompt, the Windows dialog that asks for permission or admin credentials before software can change the system. After elevation it writes to C:\Program Files\RMM Agent\, registers RMM.Agent.exe and RMM.Agent.Launcher.exe as services, adds registry Run entries so the tray components start at logon, and creates an inbound Windows Firewall rule allowing UDP port 48678 to RMM.Agent.exe. It logs its own progress with eventcreate.exe, writing "Begin installation" and "End installation. MSP360 de Success." to the event log. The sample Microsoft analysed (SHA-256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc) was signed with a certificate that has since been revoked.
The agent then does what an RMM agent is built to do: run commands for whoever controls its console. RMM.Agent.exe started PowerShell, changed the execution policy for that session, used Invoke-WebRequest to fetch ClientSetup.msi and installed it with msiexec.exe /qn, which suppresses every window. The result is a ScreenConnect client running as ScreenConnect.ClientService.exe and ScreenConnect.WindowsClient.exe, reporting to an attacker relay server. Each tool has its own service and its own server, so removing either one leaves the other connected.
What attackers are doing
Microsoft has not tied the activity to a named group. After setting up ScreenConnect, the operators used its RunFile feature, which copies a file to the endpoint and runs it, to stage tools in C:\Users\%user%\Documents\ScreenConnect\Temp\ or the OneDrive Documents equivalent. Microsoft lists about two dozen names chosen to pass as Windows, Defender or Phone Link components: WindowsUpdate.exe, WindowsSecurity_PIN.exe, WindowsSecurity_Password.exe, DefenderControl.exe, PhoneLinkPrompt.exe, HideFromControlPanel.exe, SCHider.exe, and NirSoft's WebBrowserPassView.exe and WebBrowserBookmarksView.exe. The report says they were used for information collection and credential access, including theft of passwords saved in browsers.
Microsoft also saw a separate July campaign in which FaronicsDeployAgent.exe, a legitimate deployment and remote access agent, played the same first-stage role as MSP360. Expect the specific RMM brand to keep changing.
What to do

Block unapproved RMM tools
Write down which remote access tools your organization actually uses, then enforce that list. Microsoft recommends App Control for Windows (formerly WDAC) or AppLocker publisher rules, which allow or deny executables by their signing certificate, so you can block MSP360 and ScreenConnect binaries that are not yours. In Microsoft Defender for Endpoint you can also add a certificate indicator with the block action for specific signed applications. If you do use MSP360 or ScreenConnect, require multi-factor authentication (MFA) on its console.
If you cannot roll out application control this week, there is still a stopgap. Keep users off local administrator rights so the UAC prompt demands credentials they do not have, and block or quarantine executables containing rmm_v2.5.0.67 at the mail and web gateway. Microsoft also suggests turning on cloud-delivered protection in Defender Antivirus and the attack surface reduction rules "Use advanced protection against ransomware" and "Block process creations originating from PsExec and WMI commands".
Check whether you were hit
- Look for
C:\Program Files\RMM Agent\and the RMM.Agent.exe and RMM.Agent.Launcher.exe services on machines your team never enrolled in MSP360. - List firewall rules for the agent:
Get-NetFirewallApplicationFilter -Program "C:\Program Files\RMM Agent\RMM.Agent.exe" | Get-NetFirewallRule. A hit allowing UDP 48678 matches this chain. - Look for a
C:\Program Files (x86)\ScreenConnect Client (...)folder or a ScreenConnect Client service you did not deploy, and for any files in the two ScreenConnect Temp folders above. - In the System event log, Event ID 7045 records each new service. In the Application log, search for the "MSP360 de Success" message the installer writes.
- In Defender, look for the detection
SupportScam:Win32/RogueMSP.MU!MTBand the alerts "Suspicious usage of remote management software" and "Uncommon remote access software". Microsoft publishes Advanced Hunting queries for the hash, for PowerShell started by RMM.Agent.exe running msiexec on a Temp MSI, and for RunFile launches from\Documents\and\Temp\.
Clean up and rotate
Isolate the device first, then remove both tools in the same session: the MSP360 services and folder, the ScreenConnect client, the Run entries, the UDP 48678 firewall rule and every file in the ScreenConnect Temp folders. Removing one tool and coming back later gives the operator time to reinstall it through the other.
Microsoft advises resetting the password of the account used to install the RMM services. Because browser password theft was observed, also reset every password saved in that user's browsers and sign out their active sessions, from a clean device. Then search every mailbox for the same sender, landing page domain and filename, because a phishing run rarely targets one person.
Why allow-listing RMM matters
RMM software is designed to give remote control to whoever holds the console, and a signature only says who built the tool, not who runs it. An approved list of remote access tools, enforced by application control and checked against what is actually running, covers the next campaign too, whichever RMM brand it uses.
Our security operations team hunts for unapproved remote access tools and sets up the detections above, and our safeguarding and hardening work puts application control and admin rights in order. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Microsoft Security Blog, The Hacker News, Gridinsoft, Cypro, GBHackers.
Read next
- ClickFix hides its payload in the browser cache
- A fake ChatGPT model on chatgpt.com delivered a RAT
- Antino backdoor hides its command channel in Microsoft 365
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.