HIGHphishing·

Phishing Abuses RMM Tools for Persistent Access

Microsoft has observed phishing campaigns leveraging legitimate Remote Monitoring and Management (RMM) tools, specifically MSP360 RMM and ScreenConnect. Attackers use this method to establish redundant and persistent remote access channels on compromised systems. This tactic allows threat actors to maintain control for follow-on activities, bypassing traditional security controls.

This report was researched and drafted by an AI agent and reviewed by a human analyst prior to publication. View the agent workflow →

Overview

This report details recent phishing campaigns observed by Microsoft that exploit legitimate Remote Monitoring and Management (RMM) tools. Attackers are using MSP360 RMM to deploy ScreenConnect, creating redundant and persistent remote access channels. This strategy allows threat actors to maintain control over compromised environments for follow-on activities, posing a significant risk to organizations utilizing or exposed to these tools.

Technical Analysis

  • Initial Access: Phishing campaigns serve as the initial vector, compromising user credentials or tricking users into executing malicious payloads.
  • Tool Deployment: Upon successful initial compromise, attackers deploy MSP360 RMM (formerly CloudBerry Remote Assistant) to gain initial remote control.
  • Redundant Access: MSP360 RMM is then leveraged to deploy ScreenConnect (ConnectWise Control), establishing a secondary, persistent remote access channel.
  • Purpose: This creates multiple avenues for remote control and persistence, enhancing attacker resilience against detection or remediation efforts and facilitating long-term access.
  • Affected Tools: MSP360 RMM, ScreenConnect (ConnectWise Control).

Detection

  • Monitor for the installation of legitimate RMM software (e.g., ScreenConnect.exe, cbsa.exe for MSP360 RMM) on endpoints where it is not explicitly authorized or expected by IT administration.
  • Look for suspicious process parent-child relationships, such as powershell.exe or cmd.exe spawning RMM installer executables or their agents.
  • Analyze network traffic for connections from RMM tool processes to unexpected or unapproved external IP addresses or domains.
  • Review endpoint logs for unusual service creations or modifications related to RMM tools, especially those configured for automatic startup.
  • Hunt for ScreenConnect.exe or cbsa.exe processes running on non-IT administration workstations or servers.

Sigma Detection Rules

⚠️ AI-generated detection rules. These are experimental starting points. Review field names, EventIDs, and logic against your environment’s schema before deploying. Tune to reduce false positives.

Suspicious RMM Agent Process Creation

title: Suspicious RMM Agent Process Creation
id: 4d1e2f3a-5b6c-4d8e-9f0a-1b2c3d4e5f6a
status: experimental
description: Detects the creation of processes associated with legitimate RMM tools (ScreenConnect, MSP360 RMM) that could be abused by attackers.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 1
    Image|endswith:
      - '\ScreenConnect.exe'
      - '\cbsa.exe'
  condition: selection
level: high

RMM Tool Initiating Network Connection

title: RMM Tool Initiating Network Connection
id: 7e8f9a0b-1c2d-3e4f-5a6b-7c8d9e0f1a2b
status: experimental
description: Detects network connections initiated by ScreenConnect or MSP360 RMM agents, which could indicate active remote control or data exfiltration.
logsource:
  product: windows
  service: sysmon
detection:
  selection:
    EventID: 3
    Image|endswith:
      - '\ScreenConnect.exe'
      - '\cbsa.exe'
  condition: selection
level: medium

Mitigations

  1. User Awareness Training: Educate users on identifying and reporting phishing attempts, especially those involving social engineering tactics to install software or grant remote access.
  2. Multi-Factor Authentication (MFA): Implement MFA for all remote access services, critical accounts, and RMM tool access to prevent unauthorized access even if credentials are stolen.
  3. Endpoint Detection and Response (EDR): Deploy EDR solutions to monitor for suspicious process execution, file modifications, and network connections indicative of RMM tool abuse.
  4. Application Whitelisting/Control: Restrict the execution of unauthorized applications, including RMM tools, to only approved software and specific user groups.
  5. Network Segmentation: Isolate critical systems and segment networks to limit lateral movement and the scope of compromise if an endpoint is breached.
  6. Monitor RMM Tool Usage: Strictly monitor and audit the legitimate use of RMM tools, ensuring they are only deployed and accessed by authorized personnel from approved locations and for documented purposes.

References

  • https://www.microsoft.com/en-us/security/blog/2026/09/29/phishing-abuses-rmm-tools-persistent-access/

Indicators of Compromise

No public IOCs available at time of writing.

MITRE ATT&CK

  • T1566.001 — Spearphishing Attachment
  • T1219 — Remote Access Tools
  • T1133 — External Remote Services
🤖 AI Attribution
Generated by gemini-2.5-flash ·
1,587 input / 1,277 output tokens ·
Reviewed and approved by a human analyst before publication
#phishing#high#msp360#persistence#phishing#rmm#screenconnect#windows