CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Phishing Abuses RMM Tools for Persistent Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8942

As cited

Copy frozen at (site build).

threat intel

Phishing Abuses RMM Tools for Persistent Access

In July 2026, Microsoft Defender Experts discovered phishing campaigns distributing legitimate but masqueraded MSP360 Remote Monitoring and Management (RMM) software v2.5.0.67 through social engineering lures including meeting invitations, PDF themes, and software update prompts. After installation, threat actors used the RMM agent to deploy ConnectWise ScreenConnect as a secondary remote access channel, then staged additional utilities with credential-access and information-gathering capabilities. The attack chain demonstrates how legitimate administrative tools can be chained together to establish persistent access and execute post-compromise operations while evading detection.

Why it matters: Organizations across multiple industries face phishing campaigns distributing trojanized RMM installers; security teams must restrict unapproved remote management software, enforce multifactor authentication (MFA) on approved RMM platforms, and investigate unauthorized RMM installations to reset compromised credentials and prevent lateral movement.

VendorsMicrosoftGoogleAmazon Web ServicesAdobeGitLabConnectWiseZoomCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary