Decoding the world of cybersecurity

·

Phishing turns legitimate RMM into persistence

Microsoft says attackers disguised legitimate MSP360 software as business files, then used it to install ScreenConnect and create redundant remote access to compromised systems.

Phishing turns legitimate RMM into persistence
Summary
  • Phishing campaigns delivered digitally signed MSP360 RMM software using deceptive business-themed filenames and landing pages.
  • Attackers then used MSP360 to install ConnectWise ScreenConnect as a second remote-access channel.
  • The campaign abused legitimate administrative functionality rather than exploiting vulnerabilities in either RMM product.

Attackers are using legitimate remote-management software to create durable footholds inside compromised organisations, according to Microsoft research detailing phishing campaigns that chained MSP360 RMM and ConnectWise ScreenConnect together.

The campaigns distributed digitally signed MSP360 remote monitoring and management software under filenames designed to resemble meeting invitations, PDF documents, software updates, and other ordinary business content.

Victims were directed through attacker-controlled pages and legitimate cloud-hosting services to retrieve the installer. Where a user executed it and approved privilege elevation, the MSP360 agent installed as a Windows service and provided the attacker with remote-management capability through legitimate administration software.

Microsoft then observed MSP360 being used to invoke PowerShell, retrieve a ScreenConnect MSI package, and install it silently. That created a second remote-access channel independent of the first.

Neither MSP360 nor ScreenConnect was exploited through a software vulnerability in the activity Microsoft documented. The attackers abused their intended capabilities after persuading victims to install the first application.

That distinction complicates detection. Security controls can more readily identify known malicious binaries than determine whether legitimate, approved software is being operated by an attacker.

Remote monitoring and management platforms are powerful by design. They can execute commands, deploy software, transfer files, and maintain persistent services across large numbers of endpoints. Managed service providers and internal IT teams depend on those capabilities to administer distributed estates.

An attacker using the same tooling can therefore operate through processes that resemble routine support activity.

After ScreenConnect was established, Microsoft observed additional tools transferred to compromised devices for credential access, information collection, execution, and attempts to reduce defender visibility. Several files used names resembling Windows, Microsoft Defender, security, and Phone Link components.

The campaign also relied on legitimate hosting providers including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase, allowing attackers to rotate delivery infrastructure without relying entirely on obviously malicious domains.

The wider control problem extends beyond phishing filtering. Organisations can accumulate several legitimate remote-support products because internal teams, suppliers, and managed service providers use different platforms.

Without a reliable inventory, defenders may struggle to distinguish an authorised RMM agent from an unexpected deployment because the organisation has never established which remote-management applications should exist on particular systems.

Supplier access adds another complication. A remote-management product can be legitimate, signed, patched, and business-critical while still providing a route for malicious persistence if its deployment process or administrative access is abused.

Microsoft also observed separate activity involving another legitimate remote-access product before ScreenConnect was installed, indicating that the technique is not dependent on MSP360 itself.

The campaign reflects a broader feature of modern intrusions: attackers do not always need bespoke malware when commercial administration software already supplies command execution, persistence, and file transfer. Under that model, control over who may install and operate remote-management tools becomes as important as the security of the tools themselves.

×