Microsoft’s latest threat reporting is a useful reminder that “trusted tool” does not always mean “trusted activity.” In campaigns observed in July 2026, attackers used phishing lures to push victims into running a legitimate MSP360 Remote Monitoring and Management installer. Once that RMM agent was in place, the operators used it to deploy ConnectWise ScreenConnect and create a second remote-access path into the endpoint.
The important detail for defenders is that Microsoft did not describe exploitation of ScreenConnect itself in this activity. The attacker’s advantage came from abusing normal administrative software, deceptive filenames, cloud-hosted payload delivery, and user-approved execution. That combination can slip past programs that focus only on malware hashes or known exploit traffic.
What happened
The campaigns used familiar phishing themes: meeting invitations, document review prompts, PDF or Adobe-style update pages, Zoom and Google Meet installers, e-cards, job documents, and package-delivery lures. The download infrastructure rotated across attacker-controlled sites and legitimate hosting platforms such as cloud storage or developer services.
After execution, the masqueraded MSP360 installer attempted to gain elevated privileges and install remote-management services. On systems where elevation succeeded, the RMM agent provided the initial persistent administration channel. Microsoft observed that channel launching PowerShell, downloading a ScreenConnect installer, and silently installing it through MSI execution. The result was redundant remote access: one legitimate RMM platform used to establish another.
From there, the operators used the remote-access session to transfer and run additional utilities with Windows-like names. Microsoft reported activity consistent with information collection, credential-access preparation, and attempts to blend tools into normal operating system noise.
Why this matters for SMBs and government contractors
Small businesses and government contractors often rely on outsourced IT, MSP tooling, help desk utilities, and ad hoc remote support. That creates a real detection challenge: the same class of software used to maintain laptops and servers can also give an intruder durable hands-on-keyboard access.
This is not just a phishing problem. It is an asset governance problem. If an organization cannot answer which remote administration tools are approved, where they are installed, which vendors manage them, and which accounts can deploy them, then an attacker can hide inside that ambiguity.
Defensive takeaways
- Build an RMM allowlist. Document approved remote-access tools, expected publishers, service names, management servers, and owning vendors. Treat anything outside that list as suspicious until proven otherwise.
- Inventory remote-access software continuously. Look for MSP360, ScreenConnect, Atera, AnyDesk, Splashtop, TeamViewer, RustDesk, MeshAgent, and similar tools across endpoints. The goal is not to ban all RMM — it is to make unauthorized RMM visible quickly.
- Alert on chained remote access. One RMM platform installing another remote-access client should be high-signal. MSP360 spawning PowerShell, PowerShell downloading an MSI, and msiexec silently installing ScreenConnect is the kind of behavior worth escalating.
- Restrict software installation paths. Use application control, AppLocker, Windows Defender Application Control, or EDR controls to limit unapproved signed administrative tools. Signed software can still be abused.
- Harden user elevation workflows. If users can approve UAC prompts for unknown installers from Downloads, phishing has an easy path into persistent access.
- Review firewall and service creation events. RMM installation often leaves behind services, autoruns, inbound rules, uninstall entries, and persistent agent directories.
- Reset credentials after unauthorized RMM discovery. If unapproved remote access is found, assume the actor may have observed credentials, browser data, or local files during the session.
Bulwark Black assessment
This tradecraft is effective because it abuses the gray zone between help desk operations and intrusion activity. For lean security teams, the best control is not a single IOC. It is a clear remote-management policy backed by endpoint inventory, application control, and behavior alerts for remote tools doing things they should not be doing.
For government contractors, this deserves extra attention. Remote administration software can become a path into proposal data, CUI-adjacent environments, accounting systems, cloud consoles, and privileged identity workflows. If your organization uses an MSP, now is the time to ask which RMM tools are authorized, how deployments are logged, and how unauthorized agents would be detected.
Original source: Microsoft Security Blog — Phishing Abuses RMM Tools for Persistent Access.

