Microsoft Warns of Phishing Abusing MSP360 RMM and ScreenConnect
Microsoft analyzed phishing campaigns in which attackers delivered a signed MSP360 RMM installer and then deployed ConnectWise ScreenConnect for more persistent remote access.

MSP360 RMM phishing was part of campaigns Microsoft observed in July 2026 targeting organizations in several industries. Rather than relying on an obviously malicious remote-access tool, the attackers used a legitimate, digitally signed MSP360 RMM installer, version 2.5.0.67. After it was launched, they used the tool’s agent to deploy the ConnectWise ScreenConnect client, creating a second remote-access channel.
Microsoft did not attribute the activity to a specific group. It also did not disclose the number of affected organizations, their countries, or the full extent of the damage. The company did publish indicators of compromise, hunting queries, and recommendations for identifying and restricting unauthorized remote-management tools.
MSP360 RMM phishing used common workplace lures
The attackers distributed the MSP360 RMM installer under deceptive names. They used lures that could appear credible in a workplace environment: meeting invitations, fake PDF or Adobe updates, and prompts related to Zoom and Google Meet services.
The installer was legitimate and digitally signed. This is an important difference from situations in which phishing delivers a modified malicious program. In this case, a user could install a real administrative tool that the attackers then abused to remotely manage the device.
After MSP360 RMM was launched, the attackers used its agent to run PowerShell. In this way, they quietly installed the ConnectWise ScreenConnect client. According to Microsoft, the combination of two remote-management tools provided alternative access channels. If one were detected or removed, the other could remain available in the environment.
No confirmed exploitation of a ScreenConnect vulnerability
Microsoft explicitly stated that it did not observe exploitation of a ScreenConnect vulnerability in this activity. It describes the campaign as abuse of legitimately obtained remote-management software, not as an exploit.
This circumstance is also important given the separately addressed CVE-2026-84869 vulnerability in the ScreenConnect product. ConnectWise issued a fix for it in ScreenConnect version 26.6.5, but the available information does not confirm any connection between this flaw and the campaign described by Microsoft. Patching alone therefore does not address phishing delivery or the installation of unauthorized RMM software.
After gaining access, Microsoft recorded the deployment of additional tools intended to gather information and obtain credentials. However, the public analysis does not provide a complete list of subsequent activities or specific consequences for individual targeted organizations.
What security teams should investigate
The risk mainly concerns environments that cannot enforce a list of approved remote-management tools. Organizations should check for MSP360 RMM 2.5.0.67 and unauthorized ScreenConnect clients, especially if installation followed the opening of files from the Downloads folder.
- Check PowerShell processes launched by the RMM tool’s agent.
- Look for new or unusual remote-management services.
- Verify which RMM tools are approved within the organization and which should be blocked.
- Compare telemetry and security logs with the indicators of compromise and hunting queries published by Microsoft.
Further developments could bring attribution of the actor or new information about victims. For defense, the most relevant steps for now are distinguishing between authorized and unauthorized remote-management tools and examining the chain in which phishing leads to the installation of legitimately signed RMM software.
Sources
- Microsoft Security Blog – Primary technical analysis of the campaign, the attack chain, confirmation that no exploitation of a ScreenConnect vulnerability was observed, and detection and mitigation recommendations.
- ConnectWise Security Bulletin – Confirms the separate CVE-2026-84869 vulnerability and the available ScreenConnect 26.6.5 fix; this bulletin information alone does not confirm a connection with the phishing campaign described by Microsoft.
Verified and updated: 09/30/2026 06:25



