News / Cybersecurity
Phishing Campaigns in 2026: How Cybercriminals Exploit Legitimate Remote Management Tools Published on 30 September 2026 by Christ-loisele (4 min read)
In July 2026, phishing attacks exploited fake MSP360 RMM installers to infiltrate systems. Malicious actors combined varied lures with legitimate tools to maintain persistent access, according to Microsoft Defender Experts.
Video: Zero Out Your Incident Queue - Human-led Microsoft Defender Experts for XDR (Microsoft Mechanics, YouTube)
Sophisticated Lures to Bypass Defenses
The phishing campaigns observed in July 2026 by Microsoft Defender Experts targeted organizations across multiple sectors using diversified lures. Cybercriminals distributed a falsified installer for MSP360 Remote Monitoring and Management (RMM) , a legitimate remote management tool, through meeting invitations, booby-trapped PDF documents, and fake software update alerts.
The installer, digitally signed to deceive security checks, used misleading filenames to go unnoticed. Once executed, it silently deployed ConnectWise ScreenConnect , another remote management software, creating a second access channel to compromised systems. Victims were redirected to attacker-controlled servers hosted on legitimate platforms like Amazon S3 , Cloudflare R2 , or Dropbox , as well as lesser-known services such as GitLab and Supabase .
Cybercriminals now exploit legitimate software to blend into normal IT operations, making detection far more complex.
Image: Figure 1. Attack chain showing phishing delivering a masqueraded MSP360 RMM installer that deploys ScreenConnect for persistent remote access (Microsoft Security Blog, official image)
Exploiting Legitimate Tools for Stealthy Presence
Cybercriminals abused the legitimacy of remote management tools to blend into organizations’ normal IT operations. After installing MSP360 RMM, they used PowerShell to automatically deploy ConnectWise ScreenConnect , a software commonly used by system administrators. This dual-layer access allowed them to maintain a persistent presence on compromised systems while making detection harder.
According to Microsoft Defender Experts , this tactic reflects a growing trend: malicious actors exploit legitimate software to conduct post-intrusion activities, such as data theft or credential access. Phishing emails mimicked common platforms like document-sharing portals, Zoom , Adobe Reader , or enterprise collaboration tools, further enhancing their credibility.
Image: Figure 2. Actor-controlled tax-document lure prompting download of a masqueraded MSP360 installer. (Microsoft Security Blog, official image)
What this changes here
For businesses and government agencies in Benin and West Africa, where information technology infrastructure is often less protected than in developed countries, this attack method poses an increased risk. Cybercriminals could target organizations using remote management tools like MSP360 or local alternatives, by exploiting vulnerabilities in update verification processes or internal email systems. Enhanced employee awareness of phishing techniques, along with active monitoring of suspicious activities through solutions like Microsoft Defender for Endpoint, would become essential to limit breaches.
Public administrations, often dependent on centralized management software to oversee networks, should also assess the effectiveness of their access controls and the digital signatures of installed software. The use of legitimate cloud platforms to host malicious payloads demonstrates that attackers bypass traditional filters: a behavioral analysis approach for remote management tools could prove more effective.
Image: Figure 3. Image displaying the execution of downloaded MSP360 RMM. (Microsoft Security Blog, official image)
How to protect yourself? Concrete steps
Organizations can adopt several measures to reduce their exposure. First, train employees to recognize common lures, such as unsolicited emails or suspicious update alerts. Next, strengthen controls around remote management tools by limiting their access privileges and monitoring their usage through solutions like Microsoft Defender for Endpoint , which detects unusual activities linked to these software tools. Finally, systematically verify the source of downloads, even if they come from reputable cloud services, and disable automated scripts like PowerShell when they are unnecessary.
Local IT solution providers, often used by SMEs and Beninese administrations, should also integrate mechanisms to detect abnormal behavior within their tools to limit risks related to their misuse.
Image: Figure 4. Process execution flow of the MSP360 RMM installation. (Microsoft Security Blog, official image)
Logo: MSP360 (Arseny Knyshev, Public domain) Sources