On September 29, 2026, Microsoft reported that its Defender Experts had observed phishing campaigns in July that used a disguised MSP360 Remote Monitoring and Management (RMM) installer to establish remote access and install ConnectWise ScreenConnect as a second channel. RMM software lets administrators monitor and manage computers remotely; in the activity Microsoft described, attackers abused that legitimate capability.

How the reported MSP360 chain worked

Microsoft reports phishing chain using MSP360 to install ScreenConnect
Microsoft reports phishing chain using MSP360 to install ScreenConnect

Microsoft said the campaigns used lures themed around meetings, invitations, software updates, job documents, document signing and package deliveries. One depicted a tax-document page with a download prompt for a disguised MSP360 installer.

The installer was MSP360 RMM version 2.5.0.67, which Microsoft described as legitimate and digitally signed. In successful installations, the MSP360 agent established remote access and invoked PowerShell to download a ScreenConnect installer. The ScreenConnect client was then installed silently, creating a separate remote-access channel.

Microsoft reported persistence through MSP360 services and registry entries that launched components automatically. It also observed an inbound firewall rule allowing the agent’s UDP traffic on port 48678. After ScreenConnect connected, additional tools were transferred through its RunFile function. Microsoft said some attempts stopped when User Account Control (UAC) elevation was denied or aborted, so the reported chain did not succeed in every attempt.

A separate route involving FaronicsDeployAgent

Microsoft also described separate activity in July 2026 in which FaronicsDeployAgent was used to install ScreenConnect. That was a distinct route from the phishing chain involving MSP360 RMM.

Microsoft’s assessment and recommendations

Microsoft said it did not observe exploitation of ScreenConnect itself in the activity it described. Its account concerns attackers’ use of legitimate remote-administration software to establish access.

For the observed MSP360 installer, Microsoft listed this SHA-256 indicator: 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc.

Microsoft recommended governing which RMM tools are approved, restricting unapproved management software with application-control policies, and enabling multifactor authentication for approved RMM systems where possible. It also recommended investigating unauthorized installations, resetting passwords for accounts used to install unauthorized RMM services, and strengthening cloud-delivered endpoint protection.