Skip to main content
Cyber Security 2 October 2026 7 min read

Phishing That Installs Real RMM Tools: How SMEs Can Spot Unexpected Remote Access

Iain Godding Owner / Founder / Managing Director
Mixed-media collage of padlocks, chains, bolt cutters, a safe and a fingerprint on a dark grid

Microsoft has described phishing campaigns that install a genuine, signed remote support tool and then use it to add a second one. Blocking every other remote tool usually isn't practical in a smaller business, so it needs a list of the tools that belong on each machine and an alert when any other appears.

Microsoft published research on 29 September 2026 describing phishing campaigns, first seen in July, that get staff to install a remote monitoring and management (RMM) tool. The download is the real, signed MSP360 agent under a misleading filename. Once it's running, the attackers use it to install ConnectWise ScreenConnect as a second way in. Microsoft says it didn't observe any exploitation of ScreenConnect itself.

If you run a business of 10 to 500 people, you need to know which remote access tools belong on your machines and to have someone alerted when a different one appears. Microsoft recommends blocking any tool you haven't approved, but in most smaller businesses that would also cut off suppliers who need to connect.

What Microsoft found

Microsoft Defender Experts saw the activity across multiple industries. The lures included meeting invitations, document signing requests, fake software updates, parcel notifications and job offers. Each led to a download that claimed to be what the email offered and was the renamed MSP360 installer.

The report gives no count of affected organisations and doesn't say where they are, so there's no basis for saying UK businesses were singled out. Microsoft hasn't attributed the campaigns to a named group.

The MSP360 agent asked for administrator rights, installed its own services so it would survive a restart, and then used PowerShell to install ScreenConnect silently. From there the attackers ran tools to collect credentials and data. Some of the files were hosted on ordinary cloud services such as Dropbox and Amazon S3, so blocking known bad websites wouldn't have stopped those downloads.

Why a signed installer gets past antivirus

A signed installer from an established software company is the same kind of agent IT providers install every day, so antivirus is unlikely to treat it as malicious. Its mitigations include blocking specific signed applications by their certificate in Microsoft Defender for Endpoint, since the files themselves are genuine.

CISA described the same technique in January 2023, when staff were phished into installing legitimate RMM software including ScreenConnect and AnyDesk. Microsoft's report adds a further step: the first tool installs another, so the attackers keep a way in if one of them is found and removed.

An administrator prompt after clicking an email link

The MSP360 installer couldn't set itself up without administrator rights, so a member of staff who refuses that prompt stops the attack there. Opening a meeting invitation, signing a document or updating a PDF reader shouldn't need admin access to the machine.

If people work day to day without local admin rights, they can't approve that prompt themselves, and the installer waits until someone with an admin account looks at it. Your IT provider can set up everyday accounts that way. Anyone who sees an admin prompt they weren't expecting after clicking a link should close it and report it. Include a screenshot of the prompt when you brief your team on this.

Why most SMEs can't block every other remote access tool

Microsoft's advice is to block remote access tools you haven't approved, using App Control for Business or AppLocker, and to enforce multifactor authentication (MFA) on the ones you have.

In most smaller businesses, suppliers other than the IT provider also need remote access. The accounting software vendor may connect to fix a failed update, and a line-of-business supplier may support its system with an agent of its own. Blocking everything except your IT provider's tool would stop some of those suppliers working on your systems.

Some of our own clients use other remote access tools for legitimate reasons, so we don't block them outright. We run NinjaOne as our RMM platform, behind MFA, and our monitoring alerts us when a suspect remote access tool turns up on a machine where we don't expect it.

Listing which remote access tools belong on each machine

Start by writing down which remote access tools should be on which machines, and who's responsible for each one. For most businesses the list is short: the IT provider's agent everywhere, plus a supplier's tool on the few machines that run its software.

A 40-person professional services firm might have two entries: the IT provider's RMM agent on every laptop and server, and the practice management vendor's support tool on the two finance PCs, which the vendor's support desk uses by appointment. Both are behind MFA, and someone in the firm knows when the vendor last connected.

Anything on a machine that isn't on the list needs an explanation. In the campaigns Microsoft describes, a laptop that should only carry your provider's agent would suddenly have MSP360 on it, followed shortly by ScreenConnect. Neither is malware, so a malware scan may miss them, whereas a comparison with the list shows both.

Seeing what's installed today

Your IT provider should be able to produce a software inventory from its RMM platform, listing the applications installed on each machine it manages. Ask for it and search it for remote access tools. Common ones include ScreenConnect, AnyDesk, TeamViewer, Splashtop, MSP360 and LogMeIn. Ask your provider about any you don't recognise.

Ask for the list of machines it manages as well, and compare it with the laptops and PCs you know you have. A machine missing from that list won't show up in the inventory or trigger an alert. On a single Windows PC, Settings, then Apps, then Installed apps shows what's there. An attacker's installer can use a misleading name, though, so a manual look won't replace the provider's inventory and alerts.

Questions to ask your IT provider

  1. Which remote access tools are installed across our machines today, and which of them do you manage?
  2. Is each of those tools protected by multifactor authentication?
  3. Would you be alerted if a remote access tool you don't manage appeared on one of our machines?
  4. If you were alerted, what would you do first, and when would you tell us?

If an internal IT person works alongside a provider, the questions apply to both of them, and the answers need to agree. Our comparison of in-house, outsourced and co-managed IT sets out how a co-managed split works in practice, including who holds which tools.

If you find a tool nobody can explain

Microsoft advises hunting for unapproved RMM tools and resetting credentials wherever one is found. An attacker who installed the tool may already have used it to add other software or collect passwords. Take the machine off the network and have someone look at what the tool did while it was there before you reset the passwords for the accounts used on it.

If the investigation finds more than one unexpected tool, our UK SME ransomware playbook walks through the first 60 minutes and the first 24 hours of an incident.

Getting help with remote access monitoring

If your provider can't tell you whether it would be alerted to a remote access tool that isn't on your list, set up that alerting first. We hold Cyber Essentials and ISO/IEC 27001, and our cyber security team watches for unexpected remote access tools on client machines as part of managed IT. If you'd like us to look at what's running on your machines, book a discovery call.

Frequently asked questions

Were MSP360 or ScreenConnect hacked?

No. Microsoft says it didn't observe exploitation of ScreenConnect itself. The attackers used legitimately obtained copies of both tools, delivered through phishing, so patching either product wouldn't have prevented it.

We don't use remote support tools ourselves. Does this apply to us?

Yes. In these campaigns the phishing email is what installs the tool, so a business with no remote tools of its own can still end up with one. An alert on any remote access software that isn't expected is the check that would catch it.

Should we uninstall every remote tool we don't recognise?

Check with your IT provider first, because some of those tools may belong to suppliers who legitimately support your software. If nobody can explain a tool, treat it as a possible incident. Take the machine off the network and find out what the tool did before resetting the passwords for accounts used on it, which is what Microsoft recommends.

Sources

  1. Microsoft Security Blog. Phishing abuses RMM tools for persistent access
  2. CISA. Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A)

Written by

Iain Godding

Owner / Founder / Managing Director

Iain has over 25 years’ experience delivering large-scale technology programmes across public and private sectors. As our MD he brings this enterprise-grade IT expertise to SMEs in the South West in a way that’s accessible, scalable, and commercially valuable. A champion of innovation, he’s at the forefront of applying AI and automation to help clients streamline operations, improve decision-making, and unlock new value. Iain has built a culture that prioritises innovation, service excellence, and long-term client partnerships, helping businesses of all sizes achieve more with technology. Outside work, Iain advises growing businesses as a board member and non-executive director.

View all posts by Iain

Get expert help

Ready to transform your IT?

Our team of experts is here to help you navigate technology decisions and find solutions that drive real business value.