Phishing lures install two IT admin tools for backup access

Published

A file called ZoomSetup_Installation, a PDF reader update, an RSVP e-card: in July, Microsoft Defender Experts watched phishing campaigns hand victims all three, and every one of them installed the same thing. It was not malware in the usual sense. It was a genuine, digitally signed copy of MSP360's remote monitoring and management (RMM) agent, the kind of software IT providers use to run fleets of company laptops.

That legitimacy is the point. Once the agent was running, the attackers used it to pull down a second remote-control product, ConnectWise ScreenConnect, giving themselves two independent ways back into the same machine. Microsoft detailed the activity in a report by Parasharan Raghavan, Deva Kanna Kannan and Sai Chakri with Microsoft Defender Experts, and says the campaigns targeted organizations across multiple industries. Microsoft has not attributed them to a named threat actor.

One installer behind a dozen disguises

The lures covered meeting requests, Zoom and Google Meet installation prompts, Adobe Acrobat updates, job offers, signature requests, DHL delivery notices and a statement file dressed up with the US Social Security Administration's domain. Phishing emails pointed to landing pages impersonating document-sharing portals and download sites, which sent victims to files hosted on attacker-owned domains, sites Microsoft assessed to be compromised, and mainstream cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase. Behind the rotating filenames, Microsoft found, many samples were the same MSP360 RMM v2.5.0.67 package.

The installer needs administrator rights, and here the campaign depended on the victim. When the Windows User Account Control prompt was accepted, the agent registered two services, added Run-key entries for its tray apps and opened an inbound firewall rule for UDP port 48678. When the prompt was refused, installation stopped and nothing persisted.

A second remote tool as a spare key

With MSP360 in place, its RMM.Agent.exe service launched PowerShell, fetched an installer named ClientSetup.msi from attacker infrastructure and ran it silently with msiexec. The result was a ScreenConnect client calling home to the attackers. Microsoft stresses it saw no exploitation of ScreenConnect itself; the software was abused, not broken. That is a different problem from the ScreenConnect flaw CISA ordered patched this month, and patching will not solve it.

Through ScreenConnect's RunFile feature the operators then dropped utilities named to pass as Windows, Defender or Phone Link components, among them WindowsSecurity_Password.exe, DefenderControl.exe and PhoneLinkPrompt.exe, alongside browser password and bookmark viewers. Microsoft ties the follow-on activity to information collection and credential access. It also saw a separate July intrusion that used Faronics' deployment agent, rather than MSP360, as the first foothold before installing ScreenConnect the same way.

Block every RMM tool you did not approve

Microsoft's advice centres on inventory. Decide which RMM products are sanctioned, enforce multi-factor authentication on them, and block the rest with Application Control for Windows or AppLocker publisher rules, which can refuse a vendor's signing certificate outright. Defender for Endpoint can also block specific signed applications by certificate. If an unapproved install turns up, reset the passwords of the accounts used to install it. The report includes advanced hunting queries for the MSP360 hash, PowerShell spawned by RMM.Agent.exe and ScreenConnect RunFile activity from Documents temp folders, and Defender detects the masqueraded installer as SupportScam:Win32/RogueMSP.MU!MTB.

Indicators

RMM platforms have become a favoured route in, from login bypasses like the one in N-able's N-central to campaigns like this one that skip the exploit entirely. An attacker who installs the same software your IT provider uses does not need to beat your security tools. It only needs to look ordinary.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions