The Phishing Email That Installs Your IT Tools: Microsoft Finds Attackers Using RMM Software as the Payload

Microsoft's Defender Experts documented phishing campaigns whose payload was legitimate, digitally signed IT management software. No exploit, no classic malware, and a chain that stopped whenever a user declined the admin prompt.

In July 2026, Microsoft’s Defender Experts team watched phishing campaigns deliver something that does not look like an attack at all: working, commercially licensed IT management software, properly signed, installed by the user who downloaded it.

The product was MSP360’s remote monitoring and management agent, version 2.5.0.67. It is the same category of tool a legitimate IT provider uses to patch laptops and fix printers. The attackers did not crack it or trojanise it. They renamed the installer to look like a meeting invitation, a PDF, or a Zoom update, and let people install it themselves.

Then the agent they had just installed quietly installed a second remote-access tool, so they would still have a way in if anyone noticed the first one.

What Happened

Microsoft reported campaigns hitting organisations across several industries, all using the same multi-stage delivery. Phishing emails pointed users to landing pages built to look like document-sharing portals, invitation workflows, Adobe Reader download pages, Zoom installation pages and business collaboration platforms.

The download itself came from a mix of attacker-owned domains, websites believed to be compromised, and ordinary cloud services: Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase. That matters more than it sounds. A security control that blocks suspicious-looking domains does not help when the file is sitting on the same storage service your finance team uses for invoices.

The filenames varied, the lures varied, the payload mostly did not. Microsoft found that many samples resolved to the same MSP360 installer package. Observed themes included workplace meeting requests, Zoom and Google Meet installation prompts, Adobe Acrobat and PDF reader updates, RSVP invitations and e-cards, job offer documents, document review and signature requests, and DHL package-delivery notices. That list is a fair description of a normal Tuesday inbox.

Once run from the user’s Downloads folder, the installer asked Windows for administrative privileges through a standard User Account Control prompt. Where the user approved it, installation completed: MSP360 components landed in the program files directory, two Windows services were registered (RMM.Agent.exe and RMM.Agent.Launcher.exe), autorun registry entries were created for the tray applications, and a Windows Firewall rule was added to permit inbound UDP traffic to the agent on port 48678.

Where the user declined or cancelled that prompt, Microsoft observed the installation stop. No services, no persistence, no remote access. One click, two very different outcomes.

After a successful install, the RMM agent launched PowerShell, adjusted the execution policy for that session, downloaded an MSI package from attacker infrastructure and installed it silently through msiexec with the quiet switch. The result was a ConnectWise ScreenConnect client running alongside MSP360: two independent remote-control channels on one machine.

Microsoft was specific that it did not see anyone exploiting a flaw in ScreenConnect. The attackers obtained the software legitimately and used its intended features. From there they used ScreenConnect’s built-in file-execution capability to push additional utilities into folders under the user’s Documents directory, with names chosen to resemble Windows, Microsoft Defender and Phone Link components. Several of those tools are associated with credential theft, browser data collection and reducing what defenders can see.

Microsoft also noted a parallel set of activity in the same month using a different legitimate deployment utility as the initial foothold, again ending in a ScreenConnect install. So the pattern is not tied to one vendor. Microsoft has not attributed any of it to a named group.

Why This Matters for Businesses

There is no malware here in the sense most people mean it. The binary is genuine. The certificate is valid. The vendor is real and sells to real IT departments. An antivirus product making a verdict on reputation alone has very little to object to, and a person glancing at a process list sees software that could plausibly belong there.

For a mid-market organisation, the practical exposure is that this can run for weeks without anyone forming a question. Remote sessions at odd hours look like IT doing maintenance. File transfers look like software deployment. PowerShell launched by a management agent looks like a script running on schedule. By the time the activity is recognised as hostile, the interesting part (credentials, documents, mailbox access) has usually already moved.

There is a second-order problem that tends to surface later, in an insurance claim or a client questionnaire. If an unapproved remote-access tool was installed on a company laptop and nobody detected it, the uncomfortable question is not what the attacker did. It is how long the tool sat there, and what evidence exists either way. Organisations that cannot answer that from their own logs end up paying someone else to reconstruct it.

The cost here is rarely the incident response invoice alone. It is the downtime while machines are rebuilt, the password resets across every account that touched an affected device, and the conversations with customers who want to know whether their data was in scope.

What Organizations Should Consider

The encouraging part of this story is that nothing in the chain required a zero-day. Every step depended on a setting that a business controls. These are worth taking to your IT team or provider as questions rather than instructions, because the answers tell you more than the fix does.

How many remote-access tools are installed across our devices right now? Not how many are approved. How many are present. If the honest answer is “we would have to check”, that is the finding.

If we use one RMM, is every other RMM on an endpoint an alert? This is the control that turns a quiet compromise into a noisy one. Microsoft’s own guidance points to application control and AppLocker publisher rules, which can block software based on the signing certificate, and to blocking specific signed applications through endpoint tooling. Allow-listing remote-access software used to be considered an advanced control. It now reads as a baseline one.

Can an ordinary user approve an administrative prompt? This campaign stopped dead when elevation was refused. Standing local admin rights are the difference between a failed install and a persistent foothold, which makes removing them one of the cheaper wins available. Our Zero Trust recap covers the least-privilege argument in more detail.

Do we enforce multi-factor authentication on the management tools we do use? Microsoft recommends hardening approved RMM platforms, because the tool you sanctioned is also a target.

Who sees an endpoint alert at 9pm on a Friday? Remote-access abuse is not a business-hours activity. Coverage gaps are where this kind of access matures.

If we find an unapproved agent, what is the next move? Microsoft advises resetting passwords for the accounts used to install the software, and investigating further if a system-level account performed the install. Deciding that in advance beats deciding it at speed.

How ISM Can Help

This is squarely a Managed IT Services and Cybersecurity & Risk Management problem rather than an exotic threat-hunting one. The work is unglamorous: build an accurate inventory of what is installed, agree which remote-management software is sanctioned, enforce that with application control, and strip standing administrative rights from accounts that do not need them.

Detection matters too, and it needs to be awake. Our 24/7 Help Desk & Support exists partly so that a second remote-access agent appearing on a finance laptop at two in the morning is something a human looks at rather than something a report mentions next month. Insight Managed Defense is built around that combination of hardening and monitoring.

If your organisation uses one RMM, the policy position is simple, and the technical work to enforce it is measured in days, not quarters. You can see the full range of what we cover on our services page.

Talk With Our Team

Before you ask anyone for a proposal, it is worth knowing which of the controls above you already have and which you only assume you have. Our Cyber Maturity Calculator walks through that in a few minutes and gives you a position to argue from, whether or not you ever speak to us.

If the exercise turns up something you would rather discuss than read about, our team is here.