IN July 2026, Microsoft Defender Experts observed phishing campaigns that masqueraded as legitimate MSP360 Remote Monitoring and Management (RMM) installers, distributing a signed MSP360 RMM v2.5.0.67 via meeting invitations, PDF lures, software update prompts, and other social engineering content.
Victims who interacted with the lure were directed to attacker-controlled pages and cloud services (including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase) hosting installers that used deceptive filenames designed to resemble legitimate business content. The MSP360 sample involved is identified by SHA256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc and SHA1 f34330d4c6e0aa978dc3af40360c14b31ad51127.
Analysis shows the installer gained User Account Control elevation to drop MSP360 components and services, creating persistence and enabling remote access.
Once footholds were established, the threat actor deployed a second remote-access channel by downloading and silently installing a ConnectWise ScreenConnect client, using the MSP360 RMM as the initial access point. ScreenConnect was not exploited itself; rather, threat actors leveraged both MSP360 and ScreenConnect to transfer and execute additional tools for credential access, data collection, and post‑compromise activity.
Observed post‑compromise tools included a range of utilities with filenames designed to resemble Windows, Defender, or security components, and a ScreenConnect session was used to stage further payloads in directories such as C:\Users\%user%\OneDrive\Documents\ScreenConnect\Temp\ and C:\Users\%user%\Documents\ScreenConnect\Temp\. The campaign also showed independent use of FaronicsDeployAgent[.]exe in July as an initial RMM before loading ScreenConnect.
Mitigation guidance emphasises enforcing approved RMM use, blocking unapproved software, tightening endpoint protection, and auditing for unapproved installations. Indicators of compromise include MSP360 RMM sample 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc and related domains and file artifacts detailed in the report.