Phishing Abuses RMM Tools for Persistent Access
In mid-2026, phishing campaigns abused MSP360 Remote Monitoring and Management (RMM) tools by distributing a disguised MSP360 installer via meeting invites, PDF lures, and fake software update prompts. Execution of the installer granted threat actors remote management access using legitimate administrative software. Subsequently, a ConnectWise ScreenConnect client was installed to establish a secondary remote-access channel. Attackers used multiple delivery methods including actor-controlled domains, compromised websites, and legitimate cloud services like Amazon S3 and Dropbox. Post-compromise activities included information gathering and credential theft.
AI Analysis
Technical Summary
Phishing campaigns in July 2026 targeted organizations by distributing a masqueraded MSP360 RMM installer through various social engineering lures. The legitimate MSP360 installer, once executed, provided threat actors with remote management access to compromised devices. This access was leveraged to download and install ConnectWise ScreenConnect, creating a redundant remote-access channel. Delivery mechanisms included actor-controlled domains, compromised websites, and legitimate cloud storage services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Following access establishment, attackers conducted information collection and credential access operations.
Potential Impact
The threat actors gain persistent remote access to compromised systems by abusing legitimate RMM tools, enabling them to maintain footholds within targeted environments. This access facilitates further post-compromise activities such as credential theft and information gathering, potentially leading to broader network compromise or data exfiltration. The use of trusted administrative software complicates detection and response.
Mitigation Recommendations
No specific patch or vendor advisory is available for this threat. Mitigation should focus on user awareness to recognize phishing lures and suspicious software installers. Organizations should verify the authenticity of software updates and meeting invitations before execution. Monitoring for unauthorized installation or use of RMM tools like MSP360 and ConnectWise ScreenConnect is recommended. Employ application control and endpoint detection solutions to detect or block unauthorized remote management software deployments.
Indicators of Compromise
- hash: 1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8
- hash: 499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a
- hash: 6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc
- hash: a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657
- hash: b3a2e37d066b444de23e1f98790a9fc1
- hash: e0f775585bd8580d5cdda0e7d91a370a
- hash: f5cb1defc630bd9d867458964bc4ccc8
- hash: 1798612c9445ea7c411f269d984e2aaed4bfcaf0
- hash: 5116397188cfcc1adb4ccc7738ad27697719c8eb
- hash: e81ba20e4b62ee5bb4648e57cd4811084dfab5c9
- hash: bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c
- hash: 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc
- domain: adsaw.cfd
- domain: adswre.cfd
- domain: ojsuyw.niyari.org
- hash: fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2
- hash: f34330d4c6e0aa978dc3af40360c14b31ad51127
- hash: f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97
- hash: 857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3
- hash: 6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e
- hash: 4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26
- domain: trews.cfd
- domain: swedcorry.stefneyv.com
- domain: bunstar.harej.si
- domain: sdfghj.rd-team.ru
- hash: ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0
- hash: 02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550
- hash: d49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc
- hash: 67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55
- hash: dd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64
- hash: 40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1
- hash: 3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096
- hash: 374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187
- hash: c2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208
- hash: 5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b
- hash: 19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1
- hash: d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db
- hash: d3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef
- hash: e31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3
- hash: 77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a
- hash: 06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b
- hash: 529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63
- hash: ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88
- hash: a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b
- hash: 64e1f3587c064df573b9abf0820c6dbb
- hash: 6748710d3918fcbef66c8eea944256c5
- hash: 98cb0a7fff731f805fef0b2430ad4343
- hash: d977e20c261c716faa4dbd7d0ffe1036
- hash: f9651b6e87843e2e72788c4c489378a7
- hash: 417e278a52153cf97e06a86b09636914402be898
- hash: 4fb7aa777411cb6f211f9fc8900099dbbd110dd4
- hash: 736a108843d2ea8de516e00b7539ec557c2eb45a
- hash: e6bb4b141fa499e89213c4781426f88aa95759d2
- hash: e91e42b05908e53aa063c05b7bf2a5355dbdb112
Phishing Abuses RMM Tools for Persistent Access
Description
In mid-2026, phishing campaigns abused MSP360 Remote Monitoring and Management (RMM) tools by distributing a disguised MSP360 installer via meeting invites, PDF lures, and fake software update prompts. Execution of the installer granted threat actors remote management access using legitimate administrative software. Subsequently, a ConnectWise ScreenConnect client was installed to establish a secondary remote-access channel. Attackers used multiple delivery methods including actor-controlled domains, compromised websites, and legitimate cloud services like Amazon S3 and Dropbox. Post-compromise activities included information gathering and credential theft.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Phishing campaigns in July 2026 targeted organizations by distributing a masqueraded MSP360 RMM installer through various social engineering lures. The legitimate MSP360 installer, once executed, provided threat actors with remote management access to compromised devices. This access was leveraged to download and install ConnectWise ScreenConnect, creating a redundant remote-access channel. Delivery mechanisms included actor-controlled domains, compromised websites, and legitimate cloud storage services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Following access establishment, attackers conducted information collection and credential access operations.
Potential Impact
The threat actors gain persistent remote access to compromised systems by abusing legitimate RMM tools, enabling them to maintain footholds within targeted environments. This access facilitates further post-compromise activities such as credential theft and information gathering, potentially leading to broader network compromise or data exfiltration. The use of trusted administrative software complicates detection and response.
Defensive Guidance
No specific patch or vendor advisory is available for this threat. Mitigation should focus on user awareness to recognize phishing lures and suspicious software installers. Organizations should verify the authenticity of software updates and meeting invitations before execution. Monitoring for unauthorized installation or use of RMM tools like MSP360 and ConnectWise ScreenConnect is recommended. Employ application control and endpoint detection solutions to detect or block unauthorized remote management software deployments.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/"]
- Pulse Id
- 6abc4e4a5d637b2853f15ac1
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8 | — | |
hash499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a | — | |
hash6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc | — | |
hasha93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657 | — | |
hashb3a2e37d066b444de23e1f98790a9fc1 | — | |
hashe0f775585bd8580d5cdda0e7d91a370a | — | |
hashf5cb1defc630bd9d867458964bc4ccc8 | — | |
hash1798612c9445ea7c411f269d984e2aaed4bfcaf0 | — | |
hash5116397188cfcc1adb4ccc7738ad27697719c8eb | — | |
hashe81ba20e4b62ee5bb4648e57cd4811084dfab5c9 | — | |
hashbc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c | — | |
hash108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc | — | |
hashfc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2 | — | |
hashf34330d4c6e0aa978dc3af40360c14b31ad51127 | — | |
hashf094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97 | — | |
hash857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3 | — | |
hash6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e | — | |
hash4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26 | — | |
hashceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0 | — | |
hash02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550 | — | |
hashd49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc | — | |
hash67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55 | — | |
hashdd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64 | — | |
hash40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1 | — | |
hash3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096 | — | |
hash374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187 | — | |
hashc2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208 | — | |
hash5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b | — | |
hash19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1 | — | |
hashd232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db | — | |
hashd3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef | — | |
hashe31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3 | — | |
hash77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a | — | |
hash06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b | — | |
hash529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63 | — | |
hashccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88 | — | |
hasha03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b | — | |
hash64e1f3587c064df573b9abf0820c6dbb | — | |
hash6748710d3918fcbef66c8eea944256c5 | — | |
hash98cb0a7fff731f805fef0b2430ad4343 | — | |
hashd977e20c261c716faa4dbd7d0ffe1036 | — | |
hashf9651b6e87843e2e72788c4c489378a7 | — | |
hash417e278a52153cf97e06a86b09636914402be898 | — | |
hash4fb7aa777411cb6f211f9fc8900099dbbd110dd4 | — | |
hash736a108843d2ea8de516e00b7539ec557c2eb45a | — | |
hashe6bb4b141fa499e89213c4781426f88aa95759d2 | — | |
hashe91e42b05908e53aa063c05b7bf2a5355dbdb112 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainadsaw.cfd | — | |
domainadswre.cfd | — | |
domainojsuyw.niyari.org | — | |
domaintrews.cfd | — | |
domainswedcorry.stefneyv.com | — | |
domainbunstar.harej.si | — | |
domainsdfghj.rd-team.ru | — |
Threat ID: 6abd59862a4e24523d629a6d
Added to database: 09/30/2026, 18:48:38 UTC
Last enriched: 09/30/2026, 19:06:00 UTC
Last updated: 09/30/2026, 22:07:46 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.