
Signed MSP360 v2.5.0.67 Installers Chain to ScreenConnect via UAC and PowerShell in July 2026 Phishing
Phishing delivers signed MSP360 installers that establish primary remote access then silently chain ScreenConnect. Microsoft observed the activity in July 2026 across multiple cloud staging hosts with no attribution released. The dual-RMM pattern mirrors earlier documented abuse of legitimate administrative tools.
The campaign deploys a legitimate MSP360 installer under names such as VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe. After UAC elevation the binary drops DLLs, creates two Windows services and firewall rules, then executes PowerShell to fetch and run ScreenConnect. Redundant RMM channels let operators move tools while traffic blends with routine administrative flows. Evidence shows the same operators tested Faronics Deploy Agent in parallel campaigns the same month, indicating deliberate rotation across signed remote-management binaries. No infrastructure overlap or code reuse with known groups has been published, leaving the activity unattributed. Prior RMM abuse incidents (CISA AA23-129A on AnyDesk and ConnectWise) followed identical staging patterns on cloud object storage followed by secondary RAT deployment. The current case adds registry autoruns and explicit UDP inbound allowances, tightening persistence beyond those earlier reports. Defenders should monitor for new MSP360 or Faronics service registrations paired with ScreenConnect MSI executions on endpoints that received recent meeting-invitation or PDF lures. Expect additional RMM pairs to surface within 90 days.
Threat actors: at least two new RMM pairs will be observed chaining to ScreenConnect before December 2026
Sources (2)
- [1]Primary Source(https://www.microsoft.com/en-us/security/blog/2026/09/attackers-abuse-msp360/)
- [2]Supporting Source(https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a)