Hackers Abuse MSP360 and ScreenConnect RMM Tools for Persistent Access and Credential Theft
Microsoft details a phishing campaign abusing signed MSP360 RMM installers to deploy ScreenConnect for persistent access and browser credential theft.
Microsoft observed July 2026 phishing activity across multiple industries delivering a legitimately signed MSP360 RMM v2.5.0.67 installer renamed as lures like ZoomSetup_Installation.exe and fake Adobe Acrobat updates. After UAC approval, the installer registered RMM.Agent.exe services, added autorun entries, opened inbound UDP 48678, then used PowerShell and msiexec to silently deploy ConnectWise ScreenConnect as a redundant remote-access channel. Post-access tooling included WebBrowserPassView, DefenderControl, and password-recovery utilities for credential theft and defense evasion. Microsoft found no ScreenConnect vulnerability exploited and attributed the campaign to no named actor; Faronics Deploy Agent was seen in a similar July chain.