Attackers Abuse Legitimate MSP360 RMM Installer to Deploy ScreenConnect Access
What Happened
Microsoft has reported phishing campaigns distributing installers for MSP360 (formerly CloudBerry), a legitimate Remote Monitoring and Management (RMM) tool, according to The Hacker News. The installers are disguised with deceptive file names and delivered via social-engineering lures including fake meeting invitations, PDF-themed messages, and software update prompts. Once run, the legitimate MSP360 installer establishes remote management access on the victim's machine, which Microsoft indicates has been used in conjunction with ScreenConnect as part of a dual-RMM approach.
Why It Matters
Because MSP360 is a legitimate, digitally signed RMM product, its presence on an endpoint is far less likely to trigger antivirus or EDR alerts than a custom-built remote access tool. Dual-RMM tactics — layering multiple legitimate remote management tools — give attackers redundancy: if one tool is detected and blocked, the other provides continued access. Any organization whose users can be reached by phishing (effectively all organizations) is potentially exposed, and the abuse of a trusted software category makes this activity harder to distinguish from normal IT administration.
What Defenders Should Watch For
- Unexpected installation of MSP360/CloudBerry client software on endpoints that do not use it as part of sanctioned IT operations, especially when installed under a renamed or disguised filename.
- New or unfamiliar RMM software (MSP360, ScreenConnect, or others) appearing on a host shortly after a user opens an email attachment or clicks a link referencing a meeting invite, PDF, or software update.
- The presence of more than one RMM/remote-access tool on a single endpoint, which is atypical in most managed environments and a strong signal of dual-RMM abuse.
- Phishing lures themed around calendar invitations, PDF documents, or software updates as an initial delivery vector worth reinforcing in user awareness training.
- Maintaining an allowlist of approved RMM tools and alerting on execution of any RMM installer, signed or not, that falls outside that list.
Developing Intel
This is a net-new campaign report without an associated CVE, and details on scope, targeting, and attribution may evolve as more information becomes available. For the original reporting, see The Hacker News.