HomeCyber BalkansHackers Exploit MSP360 and ScreenConnect RMM Tools for Ongoing Access and Credential...

Hackers Exploit MSP360 and ScreenConnect RMM Tools for Ongoing Access and Credential Theft

Published on

spot_img

The rise of sophisticated phishing campaigns has recently come to light, exposing a troubling trend in cybercrime that utilizes legitimate remote monitoring and management (RMM) software to gain persistent access and facilitate credential theft on Windows systems. This malicious tactic employs trusted administrative platforms, which are typically intended for executing commands, transferring files, deploying applications, and maintaining ongoing access. Such an approach allows attackers to obscure their activities and blend their malicious actions with routine IT administration tasks, significantly complicating detection efforts.

In a detailed report, Microsoft stated that they discovered no evidence suggesting that vulnerabilities within ScreenConnect software were being exploited during these attacks. Instead, the software involved was legitimately acquired and misused after victims unwittingly executed phishing payloads embedded in malicious emails. The infiltration process typically begins with phishing emails and social engineering tactics, often disguised as typical business communications that unsuspecting employees might encounter daily.

The phishing lures observed in these incidents included various forms of deceptive content such as workplace meeting invitations, prompts mimicking Zoom and Google Meet setup notifications, requests to update software like Adobe Acrobat, RSVP e-cards, job-offer documents, signature requests, tax documents, and package delivery notifications. Victims clicking on these enticing prompts were redirected to download links hosted on actor-controlled infrastructures as well as legitimate cloud services like Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. This mixed-hosting approach not only allows for rapid changes in payload delivery but also complicates network-based blocking efforts.

Upon clicking the links, victims downloaded an executable file disguised as a legitimate document or application. The downloaded file was actually a digitally signed installer for MSP360 RMM version 2.5.0.67, which had been renamed to appear benign. Some of the deceptive filenames used in this ruse included names like VIP_ECARD_INVITATION_rmm_v2.5.0.67.exe, ZoomSetup_Installation_v2.5.0.67.exe, and PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67.exe. Microsoft provided a specific SHA-256 hash for the installer involved, facilitating easier identification of the malicious software.

Once the installer was executed, it sought elevated privileges via a User Account Control (UAC) prompt. If users complied, the installer would deploy MSP360 components into the C:\Program Files\RMM Agent\ directory, registering crucial services like RMM.Agent.exe and RMM.Agent.Launcher.exe, and creating autorun entries for the MSP360 user interface. The installation process also modified the Windows Firewall settings to allow UDP traffic on port 48678 for the RMM.Agent.exe, effectively granting the attackers durable remote management access masquerading as standard IT operations. If the UAC elevation was denied or failed, the installation process would not be completed, highlighting the importance of vigilance during software installation.

This campaign, which came to light in July 2026 across multiple sectors, utilized the MSP360 RMM installer as an initial foothold before quietly deploying ConnectWise ScreenConnect. This provided a redundant remote-access channel for the attackers, thereby increasing the likelihood of maintaining control over compromised systems.

Following the establishment of ScreenConnect, attackers exploited its capabilities to transfer and execute additional malicious tools from temporary directories associated with ScreenConnect, targeting locations such as the user’s Documents and OneDrive folders. Microsoft noted instances of utilities masquerading as legitimate Windows applications, including security tools, update managers, and password retrieval apps, such as WindowsSecurity_PIN.exe, Passwords.EXE, and DefenderControl.exe. These tools aimed to collect information, access browser credentials, execute further payloads, and reduce visibility from defenders or users.

Although Microsoft did not attribute this campaign to a specific threat actor, the company observed other activities around the same time where Faronics Deploy Agent served as the initial RMM platform for installing ScreenConnect, indicating that this method is not exclusive to MSP360 alone.

To mitigate the risks associated with these types of attacks, organizations are urged to conduct thorough inventories of authorized RMM products and investigate any unapproved deployments of MSP360, ScreenConnect, or other remote administration tools. Special attention should be directed toward endpoints where both MSP360 and ScreenConnect were installed in quick succession, as well as unusual PowerShell executions initiated by RMM.Agent.exe and any unexpected installations of ClientSetup.msi.

Microsoft recommends implementing multi-factor authentication (MFA) for all authorized RMM platforms, employing App Control for Windows or AppLocker publisher rules to block unauthorized signed management tools, and enabling cloud-delivered antivirus protection. If any unauthorized RMM deployment is detected, it is crucial for organizations to reset credentials used to install its services and investigate potential system-level compromises and other persistent threats.

In conclusion, the evolution of phishing tactics that weaponize legitimate software leads to significant security vulnerabilities across various sectors. As cyber threats continue to evolve in sophistication and persistence, businesses must remain proactive in their cybersecurity measures to protect sensitive data and maintain robust defenses against these increasingly nuanced attacks.

Source link

Latest articles

Japanese Railway Operators Targeted by Cyber Attacks

Cyber Attacks Target Japanese Transport Operators: An Emerging Threat In a concerning trend for the...

AI Enhances SOC Analyst Efficiency While Hindering Skill Development

AI’s Dual Impact on Security Operations Analysts Artificial intelligence (AI) is increasingly transforming the landscape...

Discover Shadow AI and Enhance Identity Security with Accenture and Okta ISPM Webinar.

New Member Registration at ISMG: A Comprehensive Guide In a welcoming move, ISMG has reached...

Can a Superintelligence Be Imprisoned?

In the current landscape of artificial intelligence, the interplay between human oversight and machine...

More like this

Japanese Railway Operators Targeted by Cyber Attacks

Cyber Attacks Target Japanese Transport Operators: An Emerging Threat In a concerning trend for the...

AI Enhances SOC Analyst Efficiency While Hindering Skill Development

AI’s Dual Impact on Security Operations Analysts Artificial intelligence (AI) is increasingly transforming the landscape...

Discover Shadow AI and Enhance Identity Security with Accenture and Okta ISPM Webinar.

New Member Registration at ISMG: A Comprehensive Guide In a welcoming move, ISMG has reached...