Executive Summary
In July 2026, Microsoft detected sophisticated phishing campaigns where threat actors distributed legitimate MSP360 Remote Monitoring and Management (RMM) software installers disguised as meeting invitations, PDF readers, and software updates. Once executed, the digitally signed MSP360 installer established remote access and was used to deploy ConnectWise ScreenConnect as a secondary RMM channel, creating redundant access paths for attackers. The dual-RMM approach enabled threat actors to blend malicious activities with legitimate IT operations while maintaining persistent access for information collection and credential theft operations.
This incident highlights the growing trend of Living-off-the-Land (LotL) attacks where cybercriminals abuse legitimate remote administration tools to evade detection and establish persistent access, making traditional security controls less effective against these camouflaged threats.
Why This Matters Now
The abuse of legitimate RMM tools in phishing campaigns represents an escalating threat as organizations increasingly rely on remote management software, making it critical to implement zero-trust controls that can distinguish between authorized and malicious RMM usage.
Attack Path Analysis
Attackers used phishing emails with deceptive MSP360 RMM installers to establish initial access, then escalated privileges through UAC elevation and Windows service registration. They maintained persistence via dual-RMM setup (MSP360 and ScreenConnect), established command and control through legitimate remote administration channels, and positioned for data collection and credential access operations with potential for broader organizational impact.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Phishing emails delivered legitimate but deceptively-named MSP360 RMM v2.5.0.67 installers hosted on attacker-controlled infrastructure and cloud services (Amazon S3, Cloudflare R2, Dropbox, GitLab, Supabase)
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Masquerading: Match Legitimate Name or Location
Abuse Elevation Control Mechanism: Bypass User Account Control
Create or Modify System Process: Windows Service
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Impair Defenses: Disable or Modify System Firewall
Remote Access Software
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software Security Testing
Control ID: 6.4.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Device Security
Control ID: Function 2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
NIST SP 800-53 – Malicious Code Protection
Control ID: SI-3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Dual-RMM phishing attacks exploiting MSP360 and ScreenConnect create persistent backdoors, compromising IT infrastructure through legitimate administrative tools and bypassing traditional security controls.
Computer Software/Engineering
Remote access trojans leveraging signed RMM installers threaten development environments, enabling lateral movement through east-west traffic and potential source code exfiltration via compromised endpoints.
Financial Services
Sophisticated phishing campaigns using trusted RMM tools circumvent zero trust segmentation, risking sensitive financial data exposure and regulatory compliance violations across HIPAA and PCI frameworks.
Health Care / Life Sciences
Encrypted traffic exploitation and egress security bypasses through legitimate administrative channels threaten patient data protection, violating HIPAA 164.312 encryption and access control requirements.
Sources
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attackshttps://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.htmlVerified
- Microsoft Security Blog - Phishing abuses RMM tools for persistent accesshttps://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/Verified
- MSP360 RMM Tool Information - Living Off The Land RMMhttps://lolrmm.io/tools/msp360Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this MSP360 RMM-based attack by limiting lateral movement paths and reducing the attacker's ability to establish persistent dual-RMM channels across the organization.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust fabric visibility would likely have provided early detection of unauthorized RMM installation activities and flagged suspicious download patterns from multiple untrusted cloud storage platforms.
Control: Zero Trust Segmentation
Mitigation: Identity-aware segmentation policies would likely have constrained the elevated service registration process by limiting which workloads could establish persistent system-level access and reducing privilege scope.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have blocked the unauthorized firewall modifications and constrained PowerShell execution paths, limiting the attacker's ability to establish secondary RMM channels across network segments.
Control: Multicloud Visibility & Control
Mitigation: Unified visibility across cloud environments would likely have detected the anomalous dual-RMM communication patterns and constrained persistent remote access by identifying unauthorized registry modifications and suspicious traffic flows.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely have limited the scope of data collection activities and constrained file transfer capabilities through ScreenConnect channels, reducing the volume of accessible sensitive information.
Organizational impact would likely be reduced to isolated workload exposure rather than enterprise-wide compromise, with segmentation boundaries limiting ransomware deployment scope and constraining access to critical business systems.
Impact at a Glance
Affected Business Functions
- IT Operations Management
- Remote Administration Services
- Endpoint Security Management
- Network Access Control
Estimated downtime: 3 days
Estimated loss: $25,000
Potential exposure of system credentials, network configuration data, installed software inventory, and administrative access privileges. The dual-RMM setup provides persistent backdoor access enabling ongoing data collection and credential harvesting operations.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound connections to attacker infrastructure and cloud storage services
- • Deploy Threat Detection & Anomaly Response to identify suspicious remote access tool installations and dual-RMM deployment patterns
- • Enable Zero Trust Segmentation with least privilege policies to prevent lateral movement from compromised endpoints
- • Utilize Cloud Firewall (ACF) with URL filtering to block access to malicious staging infrastructure on legitimate cloud platforms
- • Establish Multicloud Visibility & Control to detect anomalous remote administration activities and policy violations across hybrid environments



