The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

In July 2026, Microsoft detected sophisticated phishing campaigns where threat actors distributed legitimate MSP360 Remote Monitoring and Management (RMM) software installers disguised as meeting invitations, PDF readers, and software updates. Once executed, the digitally signed MSP360 installer established remote access and was used to deploy ConnectWise ScreenConnect as a secondary RMM channel, creating redundant access paths for attackers. The dual-RMM approach enabled threat actors to blend malicious activities with legitimate IT operations while maintaining persistent access for information collection and credential theft operations.

This incident highlights the growing trend of Living-off-the-Land (LotL) attacks where cybercriminals abuse legitimate remote administration tools to evade detection and establish persistent access, making traditional security controls less effective against these camouflaged threats.

Why This Matters Now

The abuse of legitimate RMM tools in phishing campaigns represents an escalating threat as organizations increasingly rely on remote management software, making it critical to implement zero-trust controls that can distinguish between authorized and malicious RMM usage.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers distributed legitimate MSP360 RMM installers through phishing emails, which created Windows services, registry autorun entries, and firewall exceptions to maintain persistent remote access to compromised systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this MSP360 RMM-based attack by limiting lateral movement paths and reducing the attacker's ability to establish persistent dual-RMM channels across the organization.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Zero Trust fabric visibility would likely have provided early detection of unauthorized RMM installation activities and flagged suspicious download patterns from multiple untrusted cloud storage platforms.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-aware segmentation policies would likely have constrained the elevated service registration process by limiting which workloads could establish persistent system-level access and reducing privilege scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have blocked the unauthorized firewall modifications and constrained PowerShell execution paths, limiting the attacker's ability to establish secondary RMM channels across network segments.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Unified visibility across cloud environments would likely have detected the anomalous dual-RMM communication patterns and constrained persistent remote access by identifying unauthorized registry modifications and suspicious traffic flows.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have limited the scope of data collection activities and constrained file transfer capabilities through ScreenConnect channels, reducing the volume of accessible sensitive information.

Impact (Mitigations)

Organizational impact would likely be reduced to isolated workload exposure rather than enterprise-wide compromise, with segmentation boundaries limiting ransomware deployment scope and constraining access to critical business systems.

Impact at a Glance

Affected Business Functions

  • IT Operations Management
  • Remote Administration Services
  • Endpoint Security Management
  • Network Access Control
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $25,000

Data Exposure

Potential exposure of system credentials, network configuration data, installed software inventory, and administrative access privileges. The dual-RMM setup provides persistent backdoor access enabling ongoing data collection and credential harvesting operations.

Recommended Actions

  • • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to attacker infrastructure and cloud storage services
  • • Deploy Threat Detection & Anomaly Response to identify suspicious remote access tool installations and dual-RMM deployment patterns
  • • Enable Zero Trust Segmentation with least privilege policies to prevent lateral movement from compromised endpoints
  • • Utilize Cloud Firewall (ACF) with URL filtering to block access to malicious staging infrastructure on legitimate cloud platforms
  • • Establish Multicloud Visibility & Control to detect anomalous remote administration activities and policy violations across hybrid environments

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image