Skip to content

Security3 publishers2 min readPublished Updated

Phishers disguise signed MSP360 remote-management software as Zoom and PDF downloads

Microsoft saw phishing campaigns in July 2026 deliver a legitimate, signed MSP360 v2.5.0.67 installer disguised as Zoom, PDF and invitation files. The tool is genuine admin software, so defenders catch it by alerting on remote-management installs they never approved.

The Watch · Security desk

Illustration accompanying Phishers disguise signed MSP360 remote-management software as Zoom and PDF downloads

What happened

  • The lures posed as meeting invitations, PDF documents and software update prompts, among other social-engineering themes.
  • The installers were staged on attacker-controlled servers and on Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase.
  • The attackers used the access to deliver more tools and to run information collection and credential-access operations.
  • A separate set of attacks in July 2026 used Faronics Deploy Agent in place of MSP360, then installed ScreenConnect through it.
  • Microsoft has not attributed the activity to any known threat actor or group.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Controls that trust signed, reputable binaries let the first stage run. The misleading file name is the only part a filter could flag.
  • precedent The operators have already swapped the first-stage tool once, so a block on any single named RMM product covers one variant at most.
  • cost Removing whichever agent a responder finds first leaves the other channel open, so cleanup has to cover both products and the persistence each one set up.

The binary at the front of the chain is a digitally signed MSP360 RMM v2.5.0.67 installer [3]. Only the names are fake: ZoomSetup_Installation, SSA.GOV_STATEMENT, VIP_ECARD_INVITATION and "PDF Reader & Editor the Adobe Acrobatte", each with the real version string attached [4]. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software," the Microsoft Security Research team said [2].

On the endpoint, the installer drops several DLLs and relaunches itself through the Windows UAC elevation workflow to run privileged [6]. It enumerates installed .NET runtimes, registers two services, RMM.Agent.exe and RMM.Agent.Launcher.exe, and writes Registry autorun entries so MSP360 starts at every user sign-in [7]. It opens Windows Firewall to inbound UDP traffic on port 48678 for RMM.Agent.exe [8]. Then it uses the MSP360 agent to run PowerShell, and that PowerShell installs ScreenConnect [9]. Later payloads go through ScreenConnect's native RunFile function [10].

"The combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion," Microsoft said [14]. Across the two July sets, the first-stage tool changed from MSP360 to Faronics Deploy Agent, and ScreenConnect was the second stage both times [2]. Microsoft placed the campaign in a continuing pattern. "This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities," the company said [15].

The Hacker News report does not list Microsoft's recommended mitigations [16]. In my view the control that fits is an allowlist of the RMM products an organisation actually runs. Neither July first stage gets past it unless MSP360 or Faronics Deploy Agent is already sanctioned on that network [3]. Where one of them is, the next check is a second RMM agent arriving on a host that already has one, or an RMM agent process spawning PowerShell that installs another remote-access client [9]. The inbound UDP 48678 rule is a narrower indicator, specific to the MSP360 agent in this campaign [8].

What to watch

  • Attribution of either July set to a named group would show whether the MSP360 and Faronics waves are one operator's playbook or tradecraft shared across crews.
  • A third signed RMM product turning up ahead of ScreenConnect would confirm the first stage rotates by design.
  • Any move to revoke or restrict the signature on the MSP360 v2.5.0.67 build would change what a signature check sees.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories