Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans
Key Takeaways A recent phishing campaign is leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360 and ConnectWise ScreenConnect. Attackers are impersonating...
Key Takeaways
- A recent phishing campaign is leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360 and ConnectWise ScreenConnect.
- Attackers are impersonating common applications like Zoom and PDF readers to trick users into installing the RMM tools.
- The campaign utilizes various social engineering tactics, including fake meeting invites, document requests, and software updates.
- The use of legitimate RMM tools complicates detection, as their activity can resemble normal IT support operations.
- Organizations across multiple industries have been targeted, facing risks of persistent access, data exfiltration, and further network compromise.
Cybersecurity researchers have uncovered an active phishing campaign where attackers are masquerading as legitimate software installers, such as Zoom setup files and PDF reader downloads, to deploy remote access Trojans (RATs) on enterprise systems. This tactic transforms routine workplace interactions into vectors for unauthorized system control.
Table Of Content
The campaign employs deceptive emails that mimic various corporate communications, including meeting invitations, document sharing requests, software update notifications, and job offers. When recipients click on embedded links, they are redirected to fraudulent web pages designed to imitate legitimate document portals, Adobe download sites, Zoom installation pages, or collaborative service platforms.
Analysts at Microsoft initially detected this activity in July 2026, observing attacks against organizations spanning diverse industries. The operation delivers a genuine, digitally signed installer for MSP360 Remote Monitoring and Management (RMM), but it is rebranded with benign-sounding filenames to evade suspicion. A report shared by Microsoft indicates that this campaign has not yet been attributed to a specific threat group. This situation highlights a critical security challenge: legitimate administrative tools, when misused, can pose risks comparable to traditional malicious software, especially when their installation is controlled by an attacker.
Hackers Disguise Remote Access Tools as Zoom and PDF Installers
The primary executable in this campaign is MSP360 RMM version 2.5.0.67. Attackers present this legitimate software as various benign files, such as a meeting application, a PDF utility, an invitation, or a business document. This strategy leverages the inherent trust users place in familiar workplace applications, a common social engineering technique to reduce suspicion and encourage execution.
Upon execution, if a victim grants the necessary Windows administrator privileges, the MSP360 services are installed, along with entries configured for automatic startup. Furthermore, a firewall rule is established to permit inbound UDP traffic to the RMM agent on port 48678, ensuring the software has the necessary network access to function.
Crucially, the attackers are not exploiting any vulnerabilities within the remote control programs themselves. Instead, they are utilizing these legitimate tools as intended, but for illicit purposes. This subtle distinction makes the intrusion particularly insidious, as the activity can easily be mistaken for routine technical support, significantly complicating rapid detection and response efforts.
Not all attack attempts have been successful. In instances where users either declined or abandoned the administrator approval prompt, the installation process was halted before the remote management components could be fully deployed, preventing compromise.
Microsoft also observed a parallel campaign in July involving another legitimate deployment agent used to install ScreenConnect, demonstrating that this method of abusing trusted RMM tools is not confined to MSP360. The infrastructure supporting these attacks is dynamic, with malicious links directing users to attacker-controlled domains, compromised websites, and various cloud-hosted storage solutions like Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. This constantly shifting infrastructure mirrors the tactics seen in other weaponized PDF RMM attacks, where a convincing document serves as the initial step in a multi-stage remote access installation process.
Second Channel Extends Control
Once MSP360 is successfully deployed and active, its agent initiates a PowerShell script to download and silently install a ConnectWise ScreenConnect client. This establishes a secondary, independent channel for remote access to the compromised machine. Consequently, removing one remote access tool may not be sufficient to fully dislodge the intruder, as the second channel provides redundancy for persistence.
Following the installation of ScreenConnect, the service proceeds to transfer and execute additional utilities from temporary directories, often located within the user’s Documents or OneDrive Documents folders. Researchers have identified these post-compromise tools as being associated with credential harvesting, browser data exfiltration, stealth mechanisms (like hiding windows or cursors), and the ability to launch further malicious files. This expanded capability significantly elevates the risk of account compromise and broader network infiltration.
This multi-layered approach provides attackers with robust persistence, file transfer capabilities, and remote command execution, all while leveraging software that many IT professionals recognize and often approve. This mirrors the challenges observed in campaigns like SMOKE#SCREEN, where seemingly benign updates are exploited to establish an attacker foothold using legitimate-looking support software.
What You Should Do
- Maintain a comprehensive inventory of all approved remote management applications within your organization.
- Implement strict controls to block or audit the installation of unapproved RMM instances, leveraging publisher certificates where feasible.
- Enforce multi-factor authentication (MFA) for all sanctioned remote access tools.
- Ensure cloud-based endpoint protection solutions are fully enabled and actively monitoring.
- Thoroughly investigate any unexpected RMM installations immediately to prevent persistent connections.
- Actively hunt for indicators of compromise (IoCs) such as the listed installer hash, new MSP360 or ScreenConnect services, PowerShell processes initiated by remote agents, and silent Windows Installer activity.
- If unauthorized RMM deployment is discovered, promptly reset passwords for any accounts used in the installation process. Conduct deeper investigations if system-level credentials were involved.
- Block or audit process creation via PsExec and Windows Management Instrumentation, while also checking for potential compatibility issues on critical servers. These measures are crucial for limiting lateral movement by attackers.
- Strengthen email filtering mechanisms to reduce the likelihood of users encountering deceptive download pages.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 | 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc |
Legitimate MSP360 RMM v2.5.0.67 installer distributed under deceptive filenames; the sample was signed with a certificate that has since been revoked |
| SHA-1 | f34330d4c6e0aa978dc3af40360c14b31ad51127 |
MSP360 RMM installer hash observed in the campaign |
| SHA-256 | f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de36a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26 |
Legitimate MSP360 RMM Agent Service samples observed during the campaign |
| Domain | adswre[.]cfdtrews[.]cfdswedcorry[.]stefneyv[.]comojsuyw[.]niyari[.]orgbunstar[.]harej[.]siadsaw[.]cfdsdfghj[.]rd-team[.]ru |
Domains contacted by ScreenConnect clients during observed malicious sessions |
| SHA-256 | ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b002f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156ad49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f556cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bccdd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b6440f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b13ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6cc2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead2085bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126dbd3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53efe31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e31a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a877fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27afc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e206ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426ba93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b |
Utilities transferred or executed through ScreenConnect sessions during post-compromise activity |
| File name | VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exeZoomSetup_Installation_v2.5.0.67_ oid[redacted].exePDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exeRSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exeSSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe |
Observed deceptive MSP360 installer filenames |
| File name | ClientSetup.msiWindVerify.exeWindowsUpdate.exeWindowsSecurity_PIN.exeWindowsSecurity_Password.exeWindowsPassKey.exeSCHider.exePIN.exephonepc.exeDefenderDT.exeDefenderControl.exephonelinkupdate.exePhoneLinkPrompt.exePasswords.EXEOpenCamera.exeopen_phone_link.exeMouseHiderGUI.exeHideUL.exeHideMouseApp.dll<
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources. |



No Comment! Be the first one.