Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Accelerate Phishing Investigations: 3 Steps for SOC Teams
September 30, 2026
PaperPhone Headless Browser Network Impersonates 75,000 Mobile Devices Across 43 Countries
September 30, 2026
APT28 Targets Organizations With RedFlick Phishing Attacks
September 30, 2026
Home/Threats/Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans
Threats

Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans

Key Takeaways A recent phishing campaign is leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360 and ConnectWise ScreenConnect. Attackers are impersonating...

David kimber
David kimber
September 30, 2026 4 Min Read
2 0

Key Takeaways

  • A recent phishing campaign is leveraging legitimate remote monitoring and management (RMM) software, specifically MSP360 and ConnectWise ScreenConnect.
  • Attackers are impersonating common applications like Zoom and PDF readers to trick users into installing the RMM tools.
  • The campaign utilizes various social engineering tactics, including fake meeting invites, document requests, and software updates.
  • The use of legitimate RMM tools complicates detection, as their activity can resemble normal IT support operations.
  • Organizations across multiple industries have been targeted, facing risks of persistent access, data exfiltration, and further network compromise.

Cybersecurity researchers have uncovered an active phishing campaign where attackers are masquerading as legitimate software installers, such as Zoom setup files and PDF reader downloads, to deploy remote access Trojans (RATs) on enterprise systems. This tactic transforms routine workplace interactions into vectors for unauthorized system control.

Table Of Content

  • Key Takeaways
  • Hackers Disguise Remote Access Tools as Zoom and PDF Installers
  • Second Channel Extends Control
  • What You Should Do

The campaign employs deceptive emails that mimic various corporate communications, including meeting invitations, document sharing requests, software update notifications, and job offers. When recipients click on embedded links, they are redirected to fraudulent web pages designed to imitate legitimate document portals, Adobe download sites, Zoom installation pages, or collaborative service platforms.

Analysts at Microsoft initially detected this activity in July 2026, observing attacks against organizations spanning diverse industries. The operation delivers a genuine, digitally signed installer for MSP360 Remote Monitoring and Management (RMM), but it is rebranded with benign-sounding filenames to evade suspicion. A report shared by Microsoft indicates that this campaign has not yet been attributed to a specific threat group. This situation highlights a critical security challenge: legitimate administrative tools, when misused, can pose risks comparable to traditional malicious software, especially when their installation is controlled by an attacker.

Hackers Disguise Remote Access Tools as Zoom and PDF Installers

The primary executable in this campaign is MSP360 RMM version 2.5.0.67. Attackers present this legitimate software as various benign files, such as a meeting application, a PDF utility, an invitation, or a business document. This strategy leverages the inherent trust users place in familiar workplace applications, a common social engineering technique to reduce suspicion and encourage execution.

Upon execution, if a victim grants the necessary Windows administrator privileges, the MSP360 services are installed, along with entries configured for automatic startup. Furthermore, a firewall rule is established to permit inbound UDP traffic to the RMM agent on port 48678, ensuring the software has the necessary network access to function.

Crucially, the attackers are not exploiting any vulnerabilities within the remote control programs themselves. Instead, they are utilizing these legitimate tools as intended, but for illicit purposes. This subtle distinction makes the intrusion particularly insidious, as the activity can easily be mistaken for routine technical support, significantly complicating rapid detection and response efforts.

Not all attack attempts have been successful. In instances where users either declined or abandoned the administrator approval prompt, the installation process was halted before the remote management components could be fully deployed, preventing compromise.

Microsoft also observed a parallel campaign in July involving another legitimate deployment agent used to install ScreenConnect, demonstrating that this method of abusing trusted RMM tools is not confined to MSP360. The infrastructure supporting these attacks is dynamic, with malicious links directing users to attacker-controlled domains, compromised websites, and various cloud-hosted storage solutions like Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. This constantly shifting infrastructure mirrors the tactics seen in other weaponized PDF RMM attacks, where a convincing document serves as the initial step in a multi-stage remote access installation process.

Second Channel Extends Control

Once MSP360 is successfully deployed and active, its agent initiates a PowerShell script to download and silently install a ConnectWise ScreenConnect client. This establishes a secondary, independent channel for remote access to the compromised machine. Consequently, removing one remote access tool may not be sufficient to fully dislodge the intruder, as the second channel provides redundancy for persistence.

Following the installation of ScreenConnect, the service proceeds to transfer and execute additional utilities from temporary directories, often located within the user’s Documents or OneDrive Documents folders. Researchers have identified these post-compromise tools as being associated with credential harvesting, browser data exfiltration, stealth mechanisms (like hiding windows or cursors), and the ability to launch further malicious files. This expanded capability significantly elevates the risk of account compromise and broader network infiltration.

This multi-layered approach provides attackers with robust persistence, file transfer capabilities, and remote command execution, all while leveraging software that many IT professionals recognize and often approve. This mirrors the challenges observed in campaigns like SMOKE#SCREEN, where seemingly benign updates are exploited to establish an attacker foothold using legitimate-looking support software.

What You Should Do

  • Maintain a comprehensive inventory of all approved remote management applications within your organization.
  • Implement strict controls to block or audit the installation of unapproved RMM instances, leveraging publisher certificates where feasible.
  • Enforce multi-factor authentication (MFA) for all sanctioned remote access tools.
  • Ensure cloud-based endpoint protection solutions are fully enabled and actively monitoring.
  • Thoroughly investigate any unexpected RMM installations immediately to prevent persistent connections.
  • Actively hunt for indicators of compromise (IoCs) such as the listed installer hash, new MSP360 or ScreenConnect services, PowerShell processes initiated by remote agents, and silent Windows Installer activity.
  • If unauthorized RMM deployment is discovered, promptly reset passwords for any accounts used in the installation process. Conduct deeper investigations if system-level credentials were involved.
  • Block or audit process creation via PsExec and Windows Management Instrumentation, while also checking for potential compatibility issues on critical servers. These measures are crucial for limiting lateral movement by attackers.
  • Strengthen email filtering mechanisms to reduce the likelihood of users encountering deceptive download pages.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc Legitimate MSP360 RMM v2.5.0.67 installer distributed under deceptive filenames; the sample was signed with a certificate that has since been revoked
SHA-1 f34330d4c6e0aa978dc3af40360c14b31ad51127 MSP360 RMM installer hash observed in the campaign
SHA-256 f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97
857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3
6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e
4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26
Legitimate MSP360 RMM Agent Service samples observed during the campaign
Domain adswre[.]cfd
trews[.]cfd
swedcorry[.]stefneyv[.]com
ojsuyw[.]niyari[.]org
bunstar[.]harej[.]si
adsaw[.]cfd
sdfghj[.]rd-team[.]ru
Domains contacted by ScreenConnect clients during observed malicious sessions
SHA-256 ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0
02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550
499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a
d49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc
67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55
6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc
dd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64
40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1
3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096
374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187
bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c
c2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208
5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b
19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1
d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db
d3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef
e31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3
1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8
77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a
fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2
06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b
a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657
529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63
ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88
a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b
Utilities transferred or executed through ScreenConnect sessions during post-compromise activity
File name VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe
ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe
PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe
RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe
SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe
Observed deceptive MSP360 installer filenames
File name ClientSetup.msi
WindVerify.exe
WindowsUpdate.exe
WindowsSecurity_PIN.exe
WindowsSecurity_Password.exe
WindowsPassKey.exe
SCHider.exe
PIN.exe
phonepc.exe
DefenderDT.exe
DefenderControl.exe
phonelinkupdate.exe
PhoneLinkPrompt.exe
Passwords.EXE
OpenCamera.exe
open_phone_link.exe
MouseHiderGUI.exe
HideUL.exe
HideMouseApp.dll<

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Supply Chain Attacks Compromise Developer Machines, Lead to Cloud Breaches

Next Post

Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical PaperCut RCE Flaws Let Attackers Compromise Domain Controllers
September 30, 2026
Attackers Impersonate Zoom, PDF Installers to Deliver Remote Access Trojans
September 30, 2026
Supply Chain Attacks Compromise Developer Machines, Lead to Cloud Breaches
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us