Microsoft Security Research has warned that phishing campaigns are abusing legitimate remote monitoring and management software to establish persistent access inside organisations.

In activity observed during July 2026, attackers distributed a legitimate, digitally signed MSP360 RMM installer under deceptive filenames and lures designed to resemble workplace meeting invitations, PDF documents, software updates and collaboration portals.

How the attack chain works

The initial phishing lure convinces a user to download and run what appears to be a legitimate business file or application. The payload is actually a real remote administration installer presented under a misleading name.

Once installed and elevated, the RMM software provides remote management capability on the affected endpoint. Microsoft observed that access being used to invoke PowerShell and install a ConnectWise ScreenConnect client as a second remote-access channel.

This is abuse of legitimate software

Microsoft says it did not observe exploitation of ScreenConnect itself in this activity. The attackers were abusing legitimately obtained remote administration tools rather than exploiting a vulnerability in the software.

That distinction matters because traditional controls that block obviously malicious binaries may not stop a signed administration tool that is commonly used by IT teams.

Why redundant remote access is dangerous

Deploying a second remote-access platform gives attackers another path back into the system if the first tool is removed or detected. Microsoft observed these channels being used for follow-on activity including information collection, credential access and the deployment of additional utilities.

What defenders should do

  • Maintain an approved list of remote administration and RMM products.
  • Block or alert on unapproved remote-management software.
  • Require multifactor authentication where supported.
  • Investigate newly installed services and remote-access clients on user endpoints.
  • Monitor PowerShell and installer activity launched by RMM agents.
  • Train users to treat meeting, PDF and software-update lures with caution.

Look for unusual combinations

A single legitimate RMM tool may be normal in an IT environment. Two different remote-control products appearing unexpectedly on the same endpoint is much more suspicious, particularly if the installation follows a phishing event.

Bottom line

The campaign shows why trusted software can still become part of an intrusion chain. Organisations need policy and monitoring around remote administration tools, not only malware detection, because attackers increasingly hide inside the same utilities legitimate administrators use every day.