Attackers stack two remote-access tools to keep a foothold on Windows

Microsoft traced phishing emails that drop one remote tool, then install a second, redundant one.

CSBadmin
1 Min Read

Two remote-access tools are better than one, at least for intruders. Microsoft has described phishing runs that plant a signed MSP360 installer to open a remote-management foothold, then quietly layer on a second remote tool.

The lures mix meeting invitations, PDF-themed bait, and software-update prompts. Each carries a genuine signature from MSP360 RMM version 2.5.0.67 hidden behind a misleading file name. Staging happens on both attacker-hosted servers and mainstream cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.

Running the installer drops DLLs and triggers a Windows User Account Control elevation prompt. It then registers two services, adds autorun entries, and punches a hole in the firewall so inbound UDP traffic can reach the agent.

From that perch, the intruders push PowerShell that installs a ConnectWise ScreenConnect client, handing them a second channel. The result lets them ferry more tools in, gather data, and hide inside ordinary admin traffic. Microsoft saw a related wave that used the Faronics Deploy Agent instead of MSP360 and still ended at ScreenConnect. No known group has been named.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.