Microsoft warns of sophisticated phishing campaigns weaponizing legitimate RMM software to establish persistent unauthorized access.

The digital landscape is currently witnessing a troubling evolution in how threat actors conduct long-term espionage and data exfiltration. Microsoft’s Security Research team recently issued a critical advisory detailing a multi-stage intrusion campaign that leverages legitimate Remote Monitoring and Management (RMM) software to gain an initial foothold on enterprise networks. By disguising malicious installers as routine corporate communications—such as meeting invitations, PDF documents, and software update notifications—unidentified threat actors are bypassing traditional security perimeters by masquerading as trusted administrative tools.
This campaign, which first came to the attention of Microsoft analysts in July 2026, relies on a "living-off-the-land" strategy. Rather than deploying custom, easily detectable malware, the attackers utilize digitally signed, legitimate installers for MSP360 (formerly CloudBerry Lab). Once a user is deceived into executing these packages, the software provides the attackers with an immediate, persistent remote management channel. This method is particularly effective because security software often whitelists or ignores the behavior of well-known administrative applications, allowing the intruders to operate under the radar of standard endpoint detection and response (EDR) systems.
The Anatomy of the Intrusion Chain
The attack cycle begins with carefully crafted social engineering lures. These phishing emails are designed to exploit human curiosity or urgency, prompting users to download what appears to be a benign file. Once the victim executes the MSP360 RMM v2.5.0.67 installer, the technical sequence of the compromise unfolds rapidly.
The installer does not merely load the remote management agent; it performs a series of complex background tasks. First, the application leverages the Windows User Account Control (UAC) elevation workflow. By forcing a prompt that encourages the user to grant elevated privileges, the installer gains the necessary permissions to operate in a high-integrity context. Once privileged access is secured, the malware deploys several dynamic link libraries (DLLs) and modifies the Windows Registry. Specifically, it creates autorun entries that ensure the MSP360 agent initiates every time a user logs into the compromised machine.

Perhaps most critically, the installer alters the Windows Firewall configuration. It creates a rule to permit inbound User Datagram Protocol (UDP) traffic on port 48678, effectively punching a hole in the network perimeter that remains open for the attacker’s command-and-control (C2) communication.
Redundancy and Persistence: The Role of ScreenConnect
A defining characteristic of this campaign is the attacker’s focus on maintaining redundant access. After establishing the initial MSP360 connection, the intruders do not stop there. They utilize the existing RMM access to execute PowerShell commands, which in turn download and install a second remote-access tool: the ConnectWise ScreenConnect client.
By maintaining two separate RMM channels, the threat actors ensure that even if one service is identified and terminated by an IT department, they retain a secondary backdoor into the system. The use of ScreenConnect is particularly notable as it is a widely used, legitimate tool for remote support and administration. The attackers leverage the native "RunFile" functionality within ScreenConnect to execute additional payloads, perform credential harvesting, and conduct broad reconnaissance across the target network. This "dual-RMM" approach effectively disguises malicious post-compromise activity within the legitimate noise of standard IT operations.
Strategic Infrastructure and Deployment
The threat actors behind these campaigns have demonstrated a high level of operational discipline. The malicious installers are hosted on a variety of reputable cloud services, including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. By utilizing legitimate infrastructure providers, the attackers ensure that their malicious downloads are rarely blocked by domain reputation filters or corporate web proxies, which typically view traffic to these platforms as safe.
Microsoft’s analysis also indicates that the threat actors are flexible in their tool selection. Beyond MSP360, investigators discovered a parallel set of attacks from July 2026 that substituted MSP360 with the Faronics Deploy Agent. This indicates that the group behind these operations is likely maintaining a portfolio of RMM tools, switching between them to evade signature-based detection or to respond to security patches implemented by targeted organizations.

The Growing Threat of RMM Abuse
The abuse of RMM tools—often categorized as "LOLRMM" (Living off the Land RMM)—is a trend that has been accelerating over the past few years. RMM software is inherently designed to provide broad, high-level control over endpoint machines, making it the perfect vehicle for an attacker who wants to avoid the "loud" behavior of traditional ransomware or trojans.
Because these tools are essentially "dual-use," differentiating between an IT administrator performing a remote update and a threat actor stealing corporate data is exceptionally difficult. Traditional antivirus software, which looks for specific malicious file signatures, is often ineffective against these campaigns because the software being used is signed by a legitimate developer.
Implications for Enterprise Security
The implications of this campaign are far-reaching. The ability to gain persistent access, coupled with the ability to move laterally across a network, places any organization using remote management tools at risk. The primary challenge for security operations centers (SOCs) is that this activity blends seamlessly into the daily workload of IT departments.
To combat this, security experts suggest that organizations must adopt a more granular approach to endpoint security. Recommendations include:
- Strict Egress and Ingress Filtering: Organizations should audit their firewall logs for unauthorized connections to RMM ports, particularly those associated with software not explicitly authorized for use by the internal IT department.
- Application Control: Implementing robust Allowlisting policies ensures that only verified, digitally signed binaries can be executed, particularly those that request UAC elevation.
- Behavioral Monitoring: Instead of relying on file signatures, security teams should focus on behavioral indicators, such as a process (like an RMM installer) suddenly initiating network connections to unexpected IPs or attempting to modify firewall rules.
- Credential Hygiene: Given that the ultimate goal of these intruders is often credential theft, implementing multi-factor authentication (MFA) and strictly managing administrative privileges remain the most effective deterrents against the secondary stages of such attacks.
Chronology and Future Outlook
The identification of this campaign in July 2026 highlights the ongoing nature of these threats. While Microsoft has not attributed this specific activity to a known Advanced Persistent Threat (APT) group, the methodology mirrors tactics frequently employed by initial access brokers (IABs). These entities often gain a foothold in a network, only to sell that access to other criminal groups—such as ransomware operators—who then carry out the final stage of the attack.

As of late September 2026, the investigation remains active. The lack of clear attribution suggests a highly disciplined actor that prioritizes stealth and longevity over immediate, large-scale disruption. The shift from one RMM tool to another, such as the transition from MSP360 to Faronics, indicates that the attackers are actively monitoring their own success rates and adjusting their technical procedures to counter evolving enterprise defenses.
For organizations, the message is clear: the "trusted" status of administrative software can no longer be taken for granted. In an era where attackers hide in plain sight, visibility into the intent and behavior of every installed service is no longer a luxury—it is a fundamental requirement for maintaining a resilient and secure enterprise environment. As threat actors continue to innovate their use of legitimate tools, the industry must respond with a paradigm shift toward identity-centric and behavior-based defense mechanisms.







