"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software," the Microsoft Security Research team said.
Phishing lures and deceptive MSP360 installers
Microsoft detected, in July 2026, phishing campaigns that distributed a digitally signed MSP360 Remote Monitoring and Management (RMM) v2.5.0.67 installer under a variety of social‑engineering guises. The deceptive filenames observed in distribution include VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe, PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe, RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe, and SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe.
The installer packages were staged on attacker-controlled infrastructure and on legitimate cloud services, specifically Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase — a mix that helps hide malicious hosting behind normal, trusted platforms.
Installer behavior: UAC elevation, services, autoruns, and firewall changes
Once launched, the MSP360 installer dropped multiple DLLs and relaunches itself by invoking the Windows User Account Control (UAC) elevation workflow to run in a privileged context. The installer established persistence by deploying MSP360, registering two Windows services named RMM.Agent.exe and RMM.Agent.Launcher.exe, and creating Registry-based autorun entries so MSP360 automatically starts when users sign in.
The installer also enumerates installed .NET runtimes — a step that can guide later activity — and modifies the Windows Firewall to allow inbound UDP traffic to MSP360 (RMM.Agent.exe) on port 48678. Those changes create both a foothold and a network-access channel that looks like legitimate remote administration traffic.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildDual-RMM access: MSP360 and ConnectWise ScreenConnect
Microsoft observed attackers use the initial MSP360 foothold to download and install a ConnectWise ScreenConnect client, creating a redundant remote-access channel. The threat actor used MSP360's capabilities to execute PowerShell commands that silently installed ScreenConnect and then leveraged ScreenConnect's native RunFile functionality to transfer and run additional executables.
Microsoft described this as a multi-stage intrusion chain: the legitimate MSP360 installer gives the attacker a trusted administrative vector, which is then used to stage a second RMM product. The result is two separate remote-administration channels on the same endpoint, enabling transfer, execution, and management of additional tooling while camouflaging malicious activity within normal IT operations.
Microsoft also made clear that the activity had not been attributed to any known threat actor or group.
Faronics Deploy Agent substitution observed in July 2026
In a related pattern observed in July 2026, Microsoft said it saw attackers substitute MSP360 with Faronics Deploy Agent as the initial access vector. In those cases, Faronics Deploy Agent was used to download and install ScreenConnect, demonstrating the threat actors' willingness to try multiple RMM tools to achieve the same redundant remote-access outcome.
"This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities," Microsoft said, noting the operational logic behind using multiple trusted administration platforms in parallel.
What this means for technologists and procurement leaders, and end users
- Technologists and security teams: Watch for digitally signed MSP360 installers using deceptive filenames, the creation of services named RMM.Agent.exe and RMM.Agent.Launcher.exe, Registry autoruns that launch MSP360 at sign-in, enumeration of .NET runtimes, and firewall rule changes that open UDP port 48678 to MSP360. Also look for secondary installs of ConnectWise ScreenConnect and activity invoking ScreenConnect's RunFile function.
- Procurement leaders and enterprise IT: Be aware that legitimate RMM products — MSP360 and Faronics Deploy Agent are both implicated in observed chains — can be abused as part of staged intrusions. The use of cloud hosting platforms like Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase for distribution underscores how attackers mix trusted services into their delivery chain.
- End users: Treat unexpected meeting invitations, e‑card notifications, PDF-reader prompts, software‑update prompts, or government-themed attachments with caution. The observed baiting techniques specifically mimic those sorts of messages and delivered executable installers rather than benign documents.
The case underlines a practical problem: when administrative tools are legitimate and signed, they can be repurposed to mask malicious activity. Microsoft’s July 2026 detections show how attackers can combine a trusted RMM install with a second remote-access channel to sustain and expand access while minimizing obvious anomalies. For defenders, the central question is no longer simply whether remote-management software is present, but how and why it was installed, how it was configured, and whether parallel remote channels like ConnectWise ScreenConnect were introduced after that installation.




