Skip to main content

Phishing Abuses RMM Tools for Persistent Access

0
Medium
Published: 09/29/2026 (09/29/2026, 23:48:26 UTC)
Source: AlienVault OTX General

Description

In mid-2026, phishing campaigns abused MSP360 Remote Monitoring and Management (RMM) tools by distributing a disguised MSP360 installer via meeting invites, PDF lures, and fake software update prompts. Execution of the installer granted threat actors remote management access using legitimate administrative software. Subsequently, a ConnectWise ScreenConnect client was installed to establish a secondary remote-access channel. Attackers used multiple delivery methods including actor-controlled domains, compromised websites, and legitimate cloud services like Amazon S3 and Dropbox. Post-compromise activities included information gathering and credential theft.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 19:06:00 UTC

Technical Analysis

Phishing campaigns in July 2026 targeted organizations by distributing a masqueraded MSP360 RMM installer through various social engineering lures. The legitimate MSP360 installer, once executed, provided threat actors with remote management access to compromised devices. This access was leveraged to download and install ConnectWise ScreenConnect, creating a redundant remote-access channel. Delivery mechanisms included actor-controlled domains, compromised websites, and legitimate cloud storage services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Following access establishment, attackers conducted information collection and credential access operations.

Potential Impact

The threat actors gain persistent remote access to compromised systems by abusing legitimate RMM tools, enabling them to maintain footholds within targeted environments. This access facilitates further post-compromise activities such as credential theft and information gathering, potentially leading to broader network compromise or data exfiltration. The use of trusted administrative software complicates detection and response.

Defensive Guidance

No specific patch or vendor advisory is available for this threat. Mitigation should focus on user awareness to recognize phishing lures and suspicious software installers. Organizations should verify the authenticity of software updates and meeting invitations before execution. Monitoring for unauthorized installation or use of RMM tools like MSP360 and ConnectWise ScreenConnect is recommended. Employ application control and endpoint detection solutions to detect or block unauthorized remote management software deployments.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/"]
Pulse Id
6abc4e4a5d637b2853f15ac1

Indicators of Compromise

Hash

ValueDescriptionCopy
hash1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8
—
hash499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a
—
hash6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc
—
hasha93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657
—
hashb3a2e37d066b444de23e1f98790a9fc1
—
hashe0f775585bd8580d5cdda0e7d91a370a
—
hashf5cb1defc630bd9d867458964bc4ccc8
—
hash1798612c9445ea7c411f269d984e2aaed4bfcaf0
—
hash5116397188cfcc1adb4ccc7738ad27697719c8eb
—
hashe81ba20e4b62ee5bb4648e57cd4811084dfab5c9
—
hashbc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c
—
hash108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc
—
hashfc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2
—
hashf34330d4c6e0aa978dc3af40360c14b31ad51127
—
hashf094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97
—
hash857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3
—
hash6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e
—
hash4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26
—
hashceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0
—
hash02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550
—
hashd49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc
—
hash67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55
—
hashdd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64
—
hash40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1
—
hash3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096
—
hash374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187
—
hashc2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208
—
hash5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b
—
hash19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1
—
hashd232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db
—
hashd3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef
—
hashe31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3
—
hash77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a
—
hash06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b
—
hash529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63
—
hashccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88
—
hasha03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b
—
hash64e1f3587c064df573b9abf0820c6dbb
—
hash6748710d3918fcbef66c8eea944256c5
—
hash98cb0a7fff731f805fef0b2430ad4343
—
hashd977e20c261c716faa4dbd7d0ffe1036
—
hashf9651b6e87843e2e72788c4c489378a7
—
hash417e278a52153cf97e06a86b09636914402be898
—
hash4fb7aa777411cb6f211f9fc8900099dbbd110dd4
—
hash736a108843d2ea8de516e00b7539ec557c2eb45a
—
hashe6bb4b141fa499e89213c4781426f88aa95759d2
—
hashe91e42b05908e53aa063c05b7bf2a5355dbdb112
—

Domain

ValueDescriptionCopy
domainadsaw.cfd
—
domainadswre.cfd
—
domainojsuyw.niyari.org
—
domaintrews.cfd
—
domainswedcorry.stefneyv.com
—
domainbunstar.harej.si
—
domainsdfghj.rd-team.ru
—

Threat ID: 6abd59862a4e24523d629a6d

Added to database: 09/30/2026, 18:48:38 UTC

Last enriched: 09/30/2026, 19:06:00 UTC

Last updated: 09/30/2026, 22:07:46 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses