Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers phish employees with fake Zoom and PDF installers that deploy signed MSP360 and ScreenConnect access.
Microsoft observed a July 2026 campaign in which phishing links led to pages imitating Zoom, Adobe, and document portals. Victims who approved a Windows administrator prompt installed a legitimate signed MSP360 RMM agent, version 2.5.0.67, which opened inbound UDP port 48678 and then used PowerShell to silently install ConnectWise ScreenConnect. Follow-on utilities were associated with password theft and browser-data collection. Microsoft has not tied the activity to a named group, and installs stopped when users denied the prompt.