Phishing campaigns install remote admin tools for access
Microsoft says attackers disguise the MSP360 remote management installer as meeting invites and PDFs, then add ScreenConnect as a backup.
By Sam Reyes · Published · Updated · 4 min read

Attackers are using phishing to install legitimate remote management software on victims' computers, Microsoft warns.
The attack chain
- In July 2026, Microsoft saw phishing lures disguised as meeting invitations, PDFs and software updates.
- These delivered the real MSP360 remote monitoring and management (RMM) installer under a misleading file name.
- Once installed, attackers used it to add a ConnectWise ScreenConnect client as a second way in.
- They then deployed more tools, collected information and stole credentials.
Microsoft stresses that ScreenConnect itself was not hacked — attackers simply abused legitimate software.
Why attackers use real IT tools
RMM software is trusted, signed and common in business networks, so it often passes antivirus checks and blends in with normal IT activity. Two separate tools give attackers a backup if one is removed.
What organizations should do
- Allow only the remote management tools your IT team actually uses, and block the rest.
- Alert on new RMM software being installed.
- Teach staff that meeting invites and PDFs should never require installing software.


