As cited
Copy frozen at (site build).
threat intel
Phishing Abuses RMM Tools for Persistent Access
In July 2026, Microsoft Defender Experts discovered phishing campaigns distributing legitimate but masqueraded MSP360 Remote Monitoring and Management (RMM) software v2.5.0.67 through social engineering lures including meeting invitations, PDF themes, and software update prompts. After installation, threat actors used the RMM agent to deploy ConnectWise ScreenConnect as a secondary remote access channel, then staged additional utilities with credential-access and information-gathering capabilities. The attack chain demonstrates how legitimate administrative tools can be chained together to establish persistent access and execute post-compromise operations while evading detection.
Why it matters: Organizations across multiple industries face phishing campaigns distributing trojanized RMM installers; security teams must restrict unapproved remote management software, enforce multifactor authentication (MFA) on approved RMM platforms, and investigate unauthorized RMM installations to reset compromised credentials and prevent lateral movement.
- Source published
- First seen by Cybersecurity Tracker