THREAT actors are abusing legitimate remote monitoring and management (RMM) tools to achieve persistent, hard-to-detect access to enterprise networks. In this campaign, deceptive emails lure victims to download and run MSP360 installers that are digitally signed, with the installer prompting for User Account Control elevation.
If the user grants administrative rights, the software installs background services named RMM.Agent[.]exe and RMM.Agent.Launcher[.]exe and configures the Windows Firewall to permit inbound traffic on UDP port 48678. The attack chain then uses PowerShell to fetch an MSI from attacker infrastructure and quietly install a secondary remote tool, specifically a ConnectWise ScreenConnect client, creating a redundant remote-access channel alongside the original MSP360 deployment, according to Microsoft.
Microsoft Defender Experts describe the activity as targeting enterprise networks across multiple sectors, with operators using legitimate cloud storage services such as Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase to host payloads. Post-compromise utilities are placed in local document folders, and tools like WebBrowserPassView are used to harvest stored passwords. Some dropped tools are designed to blunt user interaction, including measures to suppress mouse movement and hide windows.
The attribution remains unattributed at this time, but the observed tradecraft—separating delivery hosts from command channels and leveraging signed software to blend with normal IT operations—suggests a financial or espionage motive and the possibility of multiple operators sharing delivery techniques.
Defenders should enforce strict software controls, audit Windows service registrations, monitor outbound connections to unauthorized RMM platforms, and apply strict privilege restrictions to limit elevation opportunities. The article notes that installations may fail if users deny the elevation prompt, providing a practical barrier to persistence.