Phishing Campaign Uses Legitimate Software to Gain Persistent Access
Microsoft has uncovered a phishing campaign that used legitimate remote management software to gain persistent access to devices. The attackers targeted organizations across multiple industries in July 2026, distributing a masqueraded MSP360 Remote Monitoring and Management (RMM) installer through meeting invitations, PDF-themed lures, and other social-engineering content.
The installer, which was designed to resemble legitimate business documents or software installers, was delivered via phishing emails that directed users to actor-controlled landing pages. Upon user interaction, victims were redirected to download locations hosted on both attacker-controlled infrastructure and legitimate cloud services.
Once executed, the MSP360 installer established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software. The attackers then used these remote administration channels to deploy additional tools and conduct post-compromise activity, including information collection and credential-access operations.
This campaign highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities. Microsoft Defender for Endpoint detects suspicious and uncommon remote-management activity, while the hunting queries and mitigations in this post can help organizations identify and restrict unapproved RMM use.