Phishing Abuses RMM Tools for Persistent Access
Microsoft has observed phishing campaigns leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically MSP360 RMM and ScreenConnect. Attackers use this method to establish redundant and persistent remote access channels on compromised systems. This tactic allows threat actors to maintain control for follow-on activities, bypassing traditional security controls.
Overview
This report details recent phishing campaigns observed by Microsoft that exploit legitimate Remote Monitoring and Management (RMM) tools. Attackers are using MSP360 RMM to deploy ScreenConnect, creating redundant and persistent remote access channels. This strategy allows threat actors to maintain control over compromised environments for follow-on activities, posing a significant risk to organizations utilizing or exposed to these tools.
Technical Analysis
- Initial Access: Phishing campaigns serve as the initial vector, compromising user credentials or tricking users into executing malicious payloads.
- Tool Deployment: Upon successful initial compromise, attackers deploy
MSP360 RMM(formerly CloudBerry Remote Assistant) to gain initial remote control. - Redundant Access:
MSP360 RMMis then leveraged to deployScreenConnect(ConnectWise Control), establishing a secondary, persistent remote access channel. - Purpose: This creates multiple avenues for remote control and persistence, enhancing attacker resilience against detection or remediation efforts and facilitating long-term access.
- Affected Tools:
MSP360 RMM,ScreenConnect(ConnectWise Control).
Detection
- Monitor for the installation of legitimate RMM software (e.g.,
ScreenConnect.exe,cbsa.exefor MSP360 RMM) on endpoints where it is not explicitly authorized or expected by IT administration. - Look for suspicious process parent-child relationships, such as
powershell.exeorcmd.exespawning RMM installer executables or their agents. - Analyze network traffic for connections from RMM tool processes to unexpected or unapproved external IP addresses or domains.
- Review endpoint logs for unusual service creations or modifications related to RMM tools, especially those configured for automatic startup.
- Hunt for
ScreenConnect.exeorcbsa.exeprocesses running on non-IT administration workstations or servers.
Sigma Detection Rules
Suspicious RMM Agent Process Creation
title: Suspicious RMM Agent Process Creation
id: 4d1e2f3a-5b6c-4d8e-9f0a-1b2c3d4e5f6a
status: experimental
description: Detects the creation of processes associated with legitimate RMM tools (ScreenConnect, MSP360 RMM) that could be abused by attackers.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 1
Image|endswith:
- '\ScreenConnect.exe'
- '\cbsa.exe'
condition: selection
level: high
RMM Tool Initiating Network Connection
title: RMM Tool Initiating Network Connection
id: 7e8f9a0b-1c2d-3e4f-5a6b-7c8d9e0f1a2b
status: experimental
description: Detects network connections initiated by ScreenConnect or MSP360 RMM agents, which could indicate active remote control or data exfiltration.
logsource:
product: windows
service: sysmon
detection:
selection:
EventID: 3
Image|endswith:
- '\ScreenConnect.exe'
- '\cbsa.exe'
condition: selection
level: medium
Mitigations
- User Awareness Training: Educate users on identifying and reporting phishing attempts, especially those involving social engineering tactics to install software or grant remote access.
- Multi-Factor Authentication (MFA): Implement MFA for all remote access services, critical accounts, and RMM tool access to prevent unauthorized access even if credentials are stolen.
- Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor for suspicious process execution, file modifications, and network connections indicative of RMM tool abuse.
- Application Whitelisting/Control: Restrict the execution of unauthorized applications, including RMM tools, to only approved software and specific user groups.
- Network Segmentation: Isolate critical systems and segment networks to limit lateral movement and the scope of compromise if an endpoint is breached.
- Monitor RMM Tool Usage: Strictly monitor and audit the legitimate use of RMM tools, ensuring they are only deployed and accessed by authorized personnel from approved locations and for documented purposes.
References
- https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/
Indicators of Compromise
No public IOCs available at time of writing.
MITRE ATT&CK
Generated by
gemini-2.5-flash ·1,587 input / 1,277 output tokens ·
Reviewed and approved by a human analyst before publication