Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs
Hackers phish employees with fake Zoom and PDF installers that deploy signed MSP360 and ScreenConnect access.
Microsoft observed a July 2026 campaign in which phishing links led to pages imitating Zoom, Adobe, and document portals. Victims who approved a Windows administrator prompt installed a legitimate signed MSP360 RMM agent, version 2.5.0.67, which opened inbound UDP port 48678 and then used PowerShell to silently install ConnectWise ScreenConnect. Follow-on utilities were associated with password theft and browser-data collection. Microsoft has not tied the activity to a named group, and installs stopped when users denied the prompt.
- July 2026 phishing lures mimicked Zoom, PDF, and document downloads.
- Signed MSP360 RMM 2.5.0.67 installed after a Windows admin prompt.
- The agent then silently installed ConnectWise ScreenConnect using PowerShell.
- Follow-on tools collected passwords and browser data from victims.
- Microsoft has not attributed the activity to a named group.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | adsaw.cfd | .]stefneyv[.]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd sdfghj[.]rd-team[.]ru Domains contacted by ScreenConnect |
| domain | adswre.cfd | M Agent Service samples observed during the campaign Domain adswre[.]cfd trews[.]cfd swedcorry[.]stefneyv[.]com ojsuyw[.]niyari[.] |
| domain | bunstar.harej.si | rews[.]cfd swedcorry[.]stefneyv[.]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd sdfghj[.]rd-team[.]ru Domains contacted by |
| domain | ojsuyw.niyari.org | Domain adswre[.]cfd trews[.]cfd swedcorry[.]stefneyv[.]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd sdfghj[.]rd-team[.]ru |
| domain | sdfghj.rd-team.ru | ]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd sdfghj[.]rd-team[.]ru Domains contacted by ScreenConnect clients during obser |
| domain | swedcorry.stefneyv.com | bserved during the campaign Domain adswre[.]cfd trews[.]cfd swedcorry[.]stefneyv[.]com ojsuyw[.]niyari[.]org bunstar[.]harej[.]si adsaw[.]cfd |
Full article918 words · extracted from cybersecuritynews.com · click to collapse
Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device.
The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the links reach pages that imitate document portals, Adobe downloads, Zoom installation pages, or collaboration services.
Microsoft analysts identified the activity in July 2026 across organizations in several industries. The operation delivers a real, digitally signed MSP360 Remote Monitoring and Management installer, but disguises it with names designed to look safe.
Microsoft said in a report shared with Cyber Security News (CSN) that it has not tied the campaign to a named group. The finding shows why trusted administration tools can be just as dangerous as traditional malware when an attacker controls their installation.
Hackers Disguise Remote Access Tools as Zoom and PDF Installers
The initial file is MSP360 RMM version 2.5.0.67, presented as a meeting app, PDF utility, invitation, or business document. The disguises exploit the same misplaced trust as signed workplace application lures that abuse familiar names to lower suspicion.
After a victim runs the file and approves the Windows administrator prompt, it installs MSP360 services and adds automatic startup entries. It also creates a firewall rule allowing inbound UDP traffic to the RMM agent on port 48678, giving the software the access it needs to communicate.
The attackers did not exploit a flaw in the remote-control programs. Instead, they used legitimate tools as intended, except the remote session belonged to them. That distinction can make the intrusion blend into normal technical-support activity and complicate quick detection.
Not every attempt succeeded. Where users denied or abandoned the administrator approval prompt, installation stopped before the remote-management components were fully deployed.
.webp)
Microsoft also saw separate July activity using another legitimate deployment agent to install ScreenConnect, showing that the approach was not limited to MSP360.
The delivery infrastructure changes frequently. Links have sent users to attacker-controlled sites, compromised websites, and cloud-hosted locations on Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.
This rotating approach echoes weaponized PDF RMM attacks, where a convincing document is only the first step toward a remote-access installation.
Second Channel Extends Control
Once MSP360 is active, its agent launches PowerShell to download an installation package and silently install a ConnectWise ScreenConnect client. That creates a second independent route into the computer, so removing one remote tool may not immediately cut off the intruder.
The ScreenConnect service then transfers and runs follow-on utilities from temporary folders in the user’s Documents or OneDrive Documents directory.
Researchers observed tools associated with password theft, browser-data collection, hiding windows or cursors, and launching further files, raising the risk of account compromise and wider network access.
This layered setup gives operators persistence, file transfer capability, and remote command execution while using software many IT teams recognize.
It reflects the same operational problem seen in the SMOKE#SCREEN remote-control campaign, where fake updates turn approved-style support software into an attacker foothold.
Organizations should maintain an inventory of approved remote-management applications and block unapproved instances, including by publisher certificate where appropriate.
They should require multi-factor authentication for sanctioned tools, keep cloud-based endpoint protection enabled, and investigate any unexpected RMM installation before it becomes a durable connection.
Security teams should also hunt for the listed installer hash, new MSP360 or ScreenConnect services, PowerShell started by the remote agent, and silent Windows Installer activity.
If an unauthorized deployment is found, passwords for accounts used to install the services should be reset, with deeper investigation when system-level credentials were involved.
Microsoft also recommends blocking or auditing process creation through PsExec and Windows Management Instrumentation, while checking for compatibility problems on some servers.
These controls target ways attackers can move between systems after gaining their first foothold. Email filters reduce chances that users reach deceptive download pages.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc | Legitimate MSP360 RMM v2.5.0.67 installer distributed under deceptive filenames; the sample was signed with a certificate that has since been revoked |
| SHA-1 | f34330d4c6e0aa978dc3af40360c14b31ad51127 | MSP360 RMM installer hash observed in the campaign |
| SHA-256 | f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de36a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26 | Legitimate MSP360 RMM Agent Service samples observed during the campaign |
| Domain | adswre[.]cfdtrews[.]cfdswedcorry[.]stefneyv[.]comojsuyw[.]niyari[.]orgbunstar[.]harej[.]siadsaw[.]cfdsdfghj[.]rd-team[.]ru | Domains contacted by ScreenConnect clients during observed malicious sessions |
| SHA-256 | ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b002f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156ad49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f556cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bccdd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b6440f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b13ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6cc2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead2085bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126dbd3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53efe31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e31a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a877fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27afc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e206ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426ba93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b | Utilities transferred or executed through ScreenConnect sessions during post-compromise activity |
| File name | VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exeZoomSetup_Installation_v2.5.0.67_ oid[redacted].exePDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exeRSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exeSSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe | Observed deceptive MSP360 installer filenames |
| File name | ClientSetup.msiWindVerify.exeWindowsUpdate.exeWindowsSecurity_PIN.exeWindowsSecurity_Password.exeWindowsPassKey.exeSCHider.exePIN.exephonepc.exeDefenderDT.exeDefenderControl.exephonelinkupdate.exePhoneLinkPrompt.exePasswords.EXEOpenCamera.exeopen_phone_link.exeMouseHiderGUI.exeHideUL.exeHideMouseApp.dllHideMouse.exeHideFromControlPanel.exeHideCursor.exeBannerHider.exeWebBrowserBookmarksView.exeWebBrowserPassView.exe | ScreenConnect installer and utilities observed during post-compromise activity |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.