VYPR
researchPublished Sep 29, 2026· 1 source

Phishing Campaigns Abuse Legitimate RMM Tools for Persistent Access

Threat actors are distributing legitimate MSP360 Remote Monitoring and Management (RMM) installers via phishing campaigns, masquerading them as meeting invitations or software updates, to establish persistent remote access.

Microsoft Defender Experts have observed sophisticated phishing campaigns targeting organizations across various industries that leverage legitimate Remote Monitoring and Management (RMM) software to establish persistent access. In July 2026, threat actors began distributing a masqueraded MSP360 RMM installer, disguised as meeting invitations, PDF documents, or software updates. Once executed, this legitimate installer, when run under a deceptive filename, establishes remote management capabilities on affected devices, providing attackers with an initial foothold using trusted administrative software.

The observed attack chain begins with phishing lures that deliver a legitimate, digitally signed MSP360 RMM v2.5.0.67 installer. These lures often impersonate document-sharing portals, invitation workflows, or software update prompts. Victims are directed to download locations hosted on both attacker-controlled infrastructure and legitimate cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. The downloaded executables are crafted with filenames designed to resemble legitimate business content, meeting invitations, or PDF documents, further deceiving users.

Following successful User Account Control (UAC) elevation, the MSP360 installer establishes its services for persistent access. It then leverages the RMM agent to invoke PowerShell, which downloads and silently installs ConnectWise ScreenConnect. This creates a secondary, redundant remote-access channel on the compromised device. Crucially, threat actors are not exploiting vulnerabilities within the RMM software itself; instead, they are abusing the legitimate administrative functionalities of these tools to blend in with normal IT operations and evade detection.

Once this secondary remote access channel is established, threat actors use it to download and execute additional tools. These tools facilitate post-compromise activities, including information gathering, credential access operations, and lateral movement within the victim's network. The use of RMM platforms is particularly attractive to attackers because these tools are designed to provide broad remote management capabilities, such as remote command execution, software deployment, and file transfer, which can be easily repurposed for malicious intent.

The campaign has employed a diverse set of payload-hosting mechanisms, allowing attackers to rapidly rotate their delivery infrastructure. By using a combination of attacker-controlled domains, compromised websites, and legitimate cloud services, the threat actors can continue distributing the same MSP360 installer while varying the lure themes and filenames to maximize their reach and minimize the chances of detection.

Microsoft Defender for Endpoint is capable of detecting suspicious and uncommon remote-management activity. The security vendor recommends that organizations implement hunting queries and mitigations to identify and restrict unapproved RMM usage. This includes monitoring for the installation of unauthorized RMM tools and scrutinizing network traffic associated with remote administration protocols.

This technique highlights a growing trend where threat actors are abusing legitimate administrative software to maintain persistence and reduce detection opportunities. By masquerading malicious activity as routine IT operations, attackers can significantly increase their chances of success and prolong their presence within compromised environments. Organizations must remain vigilant against social engineering tactics and ensure robust endpoint detection and response capabilities are in place to identify and counter such sophisticated attacks.

Synthesized by Vypr AI