Two remote-access tools are better than one, at least for intruders. Microsoft has described phishing runs that plant a signed MSP360 installer to open a remote-management foothold, then quietly layer on a second remote tool.
The lures mix meeting invitations, PDF-themed bait, and software-update prompts. Each carries a genuine signature from MSP360 RMM version 2.5.0.67 hidden behind a misleading file name. Staging happens on both attacker-hosted servers and mainstream cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.
Running the installer drops DLLs and triggers a Windows User Account Control elevation prompt. It then registers two services, adds autorun entries, and punches a hole in the firewall so inbound UDP traffic can reach the agent.
From that perch, the intruders push PowerShell that installs a ConnectWise ScreenConnect client, handing them a second channel. The result lets them ferry more tools in, gather data, and hide inside ordinary admin traffic. Microsoft saw a related wave that used the Faronics Deploy Agent instead of MSP360 and still ended at ScreenConnect. No known group has been named.
