MSP360 and ScreenConnect Dual-RMM Phishing Campaign Hunt

Threat Overview

Microsoft Security Research reported on September 29, 2026 that phishing campaigns observed in July delivered the legitimate, digitally signed MSP360 RMM 2.5.0.67 installer under deceptive meeting, document, PDF, Zoom, job, e-card, and delivery-themed filenames. After a user launched the installer and approved UAC elevation, MSP360 established persistent remote-management services. Its RMM.Agent.exe then launched PowerShell, downloaded ClientSetup.msi, and silently installed ConnectWise ScreenConnect with msiexec /qn, creating a second independent remote-access channel.

The actor subsequently used ScreenConnect RunFile functionality to transfer and execute credential-access, information-collection, and defense-evasion utilities with names imitating Windows, Defender, Phone Link, and security components. Microsoft observed similar activity in which Faronics Deploy Agent replaced MSP360 as the initial RMM before ScreenConnect installation. This is abuse of legitimate software, not exploitation of a vulnerability in MSP360 or ScreenConnect. Microsoft has not attributed the activity to a named actor.

References

Impacted Systems

  • Platform: Microsoft Windows endpoints on which a user can download and execute an installer and approve UAC elevation.
  • Software observed: Legitimate MSP360 RMM 2.5.0.67; campaign sample SHA-256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc. The observed signing certificate was later revoked.
  • Secondary access: Legitimately obtained ConnectWise ScreenConnect client components, including ScreenConnect.ClientService.exe, ScreenConnect.WindowsClient.exe, and ScreenConnect.Client.exe.
  • Alternate initial RMM: Microsoft separately observed FaronicsDeployAgent.exe used to install ScreenConnect.
  • Prerequisite: Successful social engineering, user execution, and privilege elevation; no product vulnerability is asserted.
  • Deployment model: Enterprise endpoints; greatest risk where unapproved RMM software is not application-controlled or where users can elevate installers.
  • Fixed versions: Not applicable. Control is based on application governance, allowlisting, email/web protection, and credential remediation.

Why this matters

RMM abuse is directly relevant to MSSPs because the tools are legitimate, signed, and common in administrative environments. The dual-channel pattern provides resilience if one tool is blocked, while actor-operated ScreenConnect sessions can blend with real support activity. The hunt emphasizes the rare parent-child chain, silent MSI installation, new services, RunFile execution, and post-access payloads rather than treating all RMM use as malicious.

Exploitation Status

Confirmed campaign; no vulnerability exploitation. Microsoft observed the activity in July 2026 and published technical details on September 29. The actor is unattributed. ScreenConnect was installed and abused but not exploited. MSP360 2.5.0.67 was legitimate software distributed under deceptive names; therefore, publisher trust or digital signing alone is not a safe discriminator.

What this hunt looks for

The campaign installer hash, user-path execution, RMM.Agent-to-PowerShell activity, silent ScreenConnect installation, RunFile execution, masqueraded payloads, registry/service persistence, campaign destinations, and related phishing delivery telemetry.

Required logs

Microsoft Defender for Endpoint DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and DeviceRegistryEvents; Microsoft 365 Defender EmailEvents and EmailAttachmentInfo for delivery context; and Windows Security Events as a limited process/service-install fallback.

Hunt 1 — Published MSP360 installer hash

let lookback = 90d;
let msp360Hash = "108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc";
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where SHA256 =~ msp360Hash
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, InitiatingProcessAccountName, InitiatingProcessFileName
| order by Timestamp desc

Hunt 2 — MSP360 installer launched from a user download path

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where SHA256 =~ "108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc" or ProcessVersionInfoProductName has_any ("MSP360", "RMM Agent")
| where FolderPath has_any ("\\Users\\", "\\Downloads\\", "\\Desktop\\", "\\AppData\\Local\\Temp\\")
| project Timestamp, DeviceName, AccountName, FolderPath, FileName, ProcessCommandLine, SHA256, InitiatingProcessFileName
| order by Timestamp desc

Hunt 3 — High-signal RMM.Agent to PowerShell execution

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName =~ "powershell.exe" and InitiatingProcessFileName =~ "RMM.Agent.exe"
| project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256
| order by Timestamp desc

Hunt 4 — MSP360-driven silent MSI installation

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName =~ "msiexec.exe" and ProcessCommandLine has_all (".msi", "/qn")
| where InitiatingProcessFileName in~ ("powershell.exe", "RMM.Agent.exe") or InitiatingProcessParentFileName =~ "RMM.Agent.exe"
| project Timestamp, DeviceName, AccountName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessParentFileName
| order by Timestamp desc

Hunt 5 — ScreenConnect creation shortly after MSP360 activity

let lookback = 30d;
let msp = DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName =~ "RMM.Agent.exe" or InitiatingProcessFileName =~ "RMM.Agent.exe"
| project DeviceId, DeviceName, MspTime=Timestamp;
DeviceFileEvents
| where Timestamp >= ago(lookback)
| where FileName in~ ("ScreenConnect.ClientService.exe", "ScreenConnect.WindowsClient.exe", "ScreenConnect.Client.exe", "ClientSetup.msi")
| join kind=inner msp on DeviceId, DeviceName
| where Timestamp between (MspTime .. MspTime + 2h)
| project Timestamp, DeviceName, ActionType, FolderPath, FileName, SHA256, MspTime, InitiatingProcessFileName
| order by Timestamp desc

Hunt 6 — ScreenConnect RunFile child execution

let lookback = 30d;
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName in~ ("ScreenConnect.WindowsClient.exe", "ScreenConnect.ClientService.exe", "ScreenConnect.Client.exe")
| where InitiatingProcessCommandLine has "RunFile" or ProcessCommandLine has_any ("\\Documents\\", "\\Temp\\")
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Hunt 7 — Published masqueraded follow-on payload names

let lookback = 30d;
let payloads = dynamic(["WindVerify.exe", "WindowsUpdate.exe", "WindowsSecurity_PIN.exe", "WindowsSecurity_Password.exe", "WindowsPassKey.exe", "SCHider.exe", "PIN.exe", "phonepc.exe", "DefenderDT.exe", "DefenderControl.exe", "phonelinkupdate.exe", "PhoneLinkPrompt.exe", "Passwords.EXE", "OpenCamera.exe", "open_phone_link.exe", "MouseHiderGUI.exe", "HideUL.exe", "HideMouse.exe", "HideFromControlPanel.exe", "HideCursor.exe", "BannerHider.exe", "WebBrowserBookmarksView.exe", "WebBrowserPassView.exe"]);
DeviceProcessEvents
| where Timestamp >= ago(lookback)
| where FileName in~ (payloads)
| project Timestamp, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine
| order by Timestamp desc

Hunt 8 — New MSP360 or ScreenConnect persistence

let lookback = 30d;
DeviceRegistryEvents
| where Timestamp >= ago(lookback)
| where RegistryKey has_any ("\\CurrentVersion\\Run", "\\Services\\")
| where RegistryValueData has_any ("RMM Agent", "MSP360", "ScreenConnect") or InitiatingProcessFileName in~ ("RMM.Agent.exe", "ScreenConnect.ClientService.exe", "ScreenConnect.WindowsClient.exe")
| project Timestamp, DeviceName, ActionType, RegistryKey, RegistryValueName, RegistryValueData, InitiatingProcessAccountName, InitiatingProcessFileName
| order by Timestamp desc

Hunt 9 — Campaign ScreenConnect destinations and rare RMM egress

let lookback = 30d;
let campaignDomains = dynamic(["adswre.cfd", "trews.cfd", "swedcorry.stefneyv.com", "ojsuyw.niyari.org", "bunstar.harej.si", "adsaw.cfd", "sdfghj.rd-team.ru"]);
DeviceNetworkEvents
| where Timestamp >= ago(lookback)
| where InitiatingProcessFileName in~ ("RMM.Agent.exe", "ScreenConnect.ClientService.exe", "ScreenConnect.WindowsClient.exe", "ScreenConnect.Client.exe", "FaronicsDeployAgent.exe")
| extend Host=tolower(coalesce(RemoteUrl, RemoteIP))
| where Host has_any (campaignDomains) or RemoteUrl !has_any ("screenconnect.com", "connectwise.com", "msp360.com")
| summarize FirstSeen=min(Timestamp), LastSeen=max(Timestamp), Connections=count(), Processes=make_set(InitiatingProcessFileName, 10), Commands=make_set(InitiatingProcessCommandLine, 10) by DeviceName, RemoteIP, RemotePort, RemoteUrl
| order by Connections desc

Hunt 10 — Email delivery themes with executable links or attachments

let lookback = 30d;
EmailEvents
| where Timestamp >= ago(lookback)
| where Subject has_any ("meeting", "Zoom", "Google Meet", "invitation", "RSVP", "Adobe", "PDF", "job offer", "DHL", "package delivery")
| join kind=leftouter (EmailAttachmentInfo | where Timestamp >= ago(lookback) | project NetworkMessageId, AttachmentName=FileName, AttachmentSHA256=SHA256) on NetworkMessageId
| where AttachmentName endswith ".exe" or UrlCount > 0
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Subject, DeliveryAction, DeliveryLocation, UrlCount, AttachmentName, AttachmentSHA256, NetworkMessageId
| order by Timestamp desc

Detection Notes

  • Hunts 3 through 6 form the highest-signal behavioral chain. MSP360 or ScreenConnect alone may be authorized; RMM.Agent.exe spawning PowerShell, silent MSI deployment, and a newly introduced second RMM channel are materially stronger.
  • The published MSP360 hash identifies a legitimate campaign-observed installer. A hash match requires validation of installation provenance and tenant approval; it is not proof that every copy was maliciously delivered.
  • Campaign domains are historical IOCs and may age or be sinkholed. Rare/new RMM destinations and process lineage remain useful when static IOCs no longer resolve.
  • Follow-on filenames can be renamed and some are generic. Require ScreenConnect RunFile lineage, unusual location, signer/hash context, or associated network activity.
  • Email subject hunting is noisy and delivery may occur through non-Microsoft mail systems. Endpoint behavior remains the decisive signal.
  • Endpoints without Defender for Endpoint process, file, registry, and network telemetry will not provide the multi-stage chain. Windows Security Events alone usually cannot recover file and network pivots.