Skip to content
File security for Windows systems — since 2003

How FileSure Would Have Stopped the MSP360 Dual-RMM Phishing Attack

• By Gene Allen

The Attack: Legitimate Tools, Malicious Intent

Microsoft’s Security Research team disclosed a phishing campaign in September 2026 that weaponized MSP360 Remote Monitoring and Management software. Attackers distributed digitally signed MSP360 installers disguised as meeting invitations, PDF readers, Zoom setups, and government documents. File names included:

  • VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe
  • PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exe
  • ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe

The installers were hosted on attacker infrastructure and legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Once executed, the MSP360 installer dropped multiple DLLs, triggered Windows UAC elevation to run with admin privileges, registered two Windows services (RMM.Agent.exe and RMM.Agent.Launcher.exe), created Registry autorun entries for persistence, and modified Windows Firewall rules to allow inbound UDP traffic on port 48678.

After establishing the MSP360 foothold, the attacker used it to download and install ConnectWise ScreenConnect, creating a redundant remote access channel. Both RMM tools are legitimate administrative software — which allowed the attacker to blend malicious activity into normal IT operations and reduce detection opportunities.

Microsoft also observed a variant that substituted Faronics Deploy Agent for MSP360, suggesting the threat actors are testing multiple RMM tools for initial access.

Why It Worked: The Payload Landed on Disk

This attack succeeded because the executable payload was allowed to write to the Windows file system. The phishing email delivered the installer. The user opened the attachment. The browser or email client wrote the .exe file to disk. From that point forward, the attacker controlled the machine.

Traditional antivirus and endpoint detection tools struggle with this scenario because the MSP360 and ScreenConnect installers are legitimately signed software. Signature-based detection sees a valid certificate and allows the write operation. Behavioral detection only triggers after the installer runs — by which time the attacker already has persistent access and firewall rules configured.

The upstream failure is simple: email clients and browsers should not be writing executable files to disk. That’s not their job. When Outlook or Chrome writes a .exe or .dll file, it’s either a user downloading software intentionally or a phishing payload being delivered. In enterprise environments, software installation should go through IT — not through an email attachment.

How FileSure Blocks It: Kernel-Level File Write Control

FileSure Defend operates at the Windows kernel level via a filter driver. It intercepts file system operations before they complete — including write and create operations. This means FileSure can block the MSP360 installer from ever landing on disk, regardless of whether it’s digitally signed or flagged by antivirus.

The relevant FileSure rule configuration:

Prevent Phishing Payload Delivery (Email Client Executable Writes)

  • File name filter: *.exe;*.dll;*.bat;*.cmd;*.ps1;*.vbs;*.js
  • Program name filter: outlook.exe;thunderbird.exe;chrome.exe;firefox.exe;msedge.exe;iexplore.exe
  • Operations: Write, Create
  • Drive type: All local drives
  • Result: Email clients and browsers cannot write executable files to disk. Documents, images, and archives are unaffected. Users can still download software through IT-approved channels.

When the user clicks the phishing attachment, Outlook attempts to write VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe to the Downloads folder. FileSure intercepts the write operation at the kernel level, blocks it, and logs the event with full context: which user, which file, which program, exact timestamp.

The payload never touches the file system. The installer never runs. MSP360 is never installed. ScreenConnect is never downloaded. The attacker gets nothing.

This isn’t behavioral detection or signature matching — it’s file system access control. The rule doesn’t care whether MSP360 is legitimate software or whether the installer is signed. It enforces a simple policy: email clients don’t write executables. Period.

The Operational Reality

MSPs and enterprise IT teams deal with phishing campaigns every day. Users click attachments. Attackers rotate domains, file names, and hosting infrastructure faster than signature databases update. Dual-RMM attacks like this one are particularly dangerous because the tools blend into normal administrative activity — making post-compromise detection difficult.

FileSure addresses the problem at the file system operation layer. It doesn’t matter what the phishing email looks like, which cloud service hosts the payload, or whether the installer is signed. If the delivery vector involves writing an executable file to disk from an email client or browser, FileSure blocks it before the attack starts.

The MSP360 campaign Microsoft disclosed required file write operations to succeed. Control those operations, stop the attack.

Start a free 21-day trial at bystorm.com — full functionality, no credit card required.


Source: Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Category: Threat Intelligence

Tags: msp360, screenconnect, phishing, rmm abuse, dual-rmm attack, kernel filter driver, file system security, payload delivery blocking

Gene Allen

Written by

Gene Allen

Gene Allen is a Windows file security expert with over 20 years of experience developing kernel-level solutions that protect enterprise data from ransomware, unauthorized access, and data loss. As founder of ByStorm Software, he architected FileSure — a patented file auditing and security platform trusted by 200+ organizations across healthcare, financial services, and government. Gene holds two U.S. patents in file system security and access control.

Ready to protect your organization?

Start your free 21-day trial today. No credit card required.

Start Your Free 21-Day Trial