The Attack: Legitimate Tools, Malicious Intent
Microsoft’s Security Research team disclosed a phishing campaign in September 2026 that weaponized MSP360 Remote Monitoring and Management software. Attackers distributed digitally signed MSP360 installers disguised as meeting invitations, PDF readers, Zoom setups, and government documents. File names included:
VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exePDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exeZoomSetup_Installation_v2.5.0.67_oid[redacted].exe
The installers were hosted on attacker infrastructure and legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Once executed, the MSP360 installer dropped multiple DLLs, triggered Windows UAC elevation to run with admin privileges, registered two Windows services (RMM.Agent.exe and RMM.Agent.Launcher.exe), created Registry autorun entries for persistence, and modified Windows Firewall rules to allow inbound UDP traffic on port 48678.
After establishing the MSP360 foothold, the attacker used it to download and install ConnectWise ScreenConnect, creating a redundant remote access channel. Both RMM tools are legitimate administrative software — which allowed the attacker to blend malicious activity into normal IT operations and reduce detection opportunities.
Microsoft also observed a variant that substituted Faronics Deploy Agent for MSP360, suggesting the threat actors are testing multiple RMM tools for initial access.
Why It Worked: The Payload Landed on Disk
This attack succeeded because the executable payload was allowed to write to the Windows file system. The phishing email delivered the installer. The user opened the attachment. The browser or email client wrote the .exe file to disk. From that point forward, the attacker controlled the machine.
Traditional antivirus and endpoint detection tools struggle with this scenario because the MSP360 and ScreenConnect installers are legitimately signed software. Signature-based detection sees a valid certificate and allows the write operation. Behavioral detection only triggers after the installer runs — by which time the attacker already has persistent access and firewall rules configured.
The upstream failure is simple: email clients and browsers should not be writing executable files to disk. That’s not their job. When Outlook or Chrome writes a .exe or .dll file, it’s either a user downloading software intentionally or a phishing payload being delivered. In enterprise environments, software installation should go through IT — not through an email attachment.
How FileSure Blocks It: Kernel-Level File Write Control
FileSure Defend operates at the Windows kernel level via a filter driver. It intercepts file system operations before they complete — including write and create operations. This means FileSure can block the MSP360 installer from ever landing on disk, regardless of whether it’s digitally signed or flagged by antivirus.
The relevant FileSure rule configuration:
Prevent Phishing Payload Delivery (Email Client Executable Writes)
- File name filter:
*.exe;*.dll;*.bat;*.cmd;*.ps1;*.vbs;*.js - Program name filter:
outlook.exe;thunderbird.exe;chrome.exe;firefox.exe;msedge.exe;iexplore.exe - Operations: Write, Create
- Drive type: All local drives
- Result: Email clients and browsers cannot write executable files to disk. Documents, images, and archives are unaffected. Users can still download software through IT-approved channels.
When the user clicks the phishing attachment, Outlook attempts to write VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe to the Downloads folder. FileSure intercepts the write operation at the kernel level, blocks it, and logs the event with full context: which user, which file, which program, exact timestamp.
The payload never touches the file system. The installer never runs. MSP360 is never installed. ScreenConnect is never downloaded. The attacker gets nothing.
This isn’t behavioral detection or signature matching — it’s file system access control. The rule doesn’t care whether MSP360 is legitimate software or whether the installer is signed. It enforces a simple policy: email clients don’t write executables. Period.
The Operational Reality
MSPs and enterprise IT teams deal with phishing campaigns every day. Users click attachments. Attackers rotate domains, file names, and hosting infrastructure faster than signature databases update. Dual-RMM attacks like this one are particularly dangerous because the tools blend into normal administrative activity — making post-compromise detection difficult.
FileSure addresses the problem at the file system operation layer. It doesn’t matter what the phishing email looks like, which cloud service hosts the payload, or whether the installer is signed. If the delivery vector involves writing an executable file to disk from an email client or browser, FileSure blocks it before the attack starts.
The MSP360 campaign Microsoft disclosed required file write operations to succeed. Control those operations, stop the attack.
Start a free 21-day trial at bystorm.com — full functionality, no credit card required.
Source: Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Category: Threat Intelligence
Tags: msp360, screenconnect, phishing, rmm abuse, dual-rmm attack, kernel filter driver, file system security, payload delivery blocking