Microsoft has warned that threat actors are distributing a legitimate, signed installer for MSP360 Remote Monitoring and Management (RMM) software through phishing emails — then deploying a second remote-access tool, ScreenConnect, on top of it.

According to a report from The Hacker News, the campaigns present the installer under meeting invitation-themed lures, PDF-themed content, software update prompts, and other social-engineering messages. Once executed, Microsoft said, the legitimate MSP360 installer — distributed under a deceptive file name — established remote management access on the affected machines.

Microsoft did not name a threat actor in the advisory, nor did it identify a specific managed service provider as the initial access vector. The Hacker News frames the campaigns as a reusable sequence of steps rather than the work of a single identified group.

How the chain works

The report says the MSP360 installer establishes initial remote management access using entirely benign software. With that foothold already in place, attackers then install ScreenConnect on top of it, giving them a second remote-access channel on the same endpoint.

Both tools are legitimate, signed products — the kind that endpoint protection platforms are designed not to flag when delivered through normal channels. Signature-based detection, by design, is not built to challenge them.

The layering, as described in the report, appears deliberate. If a defender removes one tool, the second one can keep the intrusion alive. Both tools also generate traffic that looks like routine administration activity — remote sessions, management agents, update traffic — which tends to blend into the background of a managed environment. The practical effect is that the detection question shifts from "is this software malicious?" to "was this software supposed to be installed here?"

Why managed service providers are exposed

Management agents are deployed in bulk, installed with elevated rights, and are routinely expected to be present on endpoints. That expectation is what makes them an effective intrusion vector in this model.

On the technique described in the report, managed service providers appear particularly exposed. A single RMM foothold on one managed endpoint can cascade into a cross-customer incident, and reconstructing the tool inventory on an endpoint managed by a third party is harder than auditing software the business has consciously approved. The report does not name any MSP as a target.

What defenders can do

Defenders can consider the following actions; the direction is consistent with the mitigations discussed in the Microsoft advisory referenced by The Hacker News, and with broader community guidance on RMM abuse:

  1. Inventory every RMM tool actually deployed across the estate, including third-party agents installed by managed service providers or acquired through corporate transactions. Anything not on that sanctioned list should be treated as an incident, not an accepted risk.
  2. Monitor installation events, not just payloads. Signature-based detection is structurally blind to this technique. Application allowlisting, install-time telemetry, and alerting on unexpected installer activity cover the gap endpoint protection leaves open.
  3. Restrict who can install remote-management tooling, and treat any software update prompt that arrives by email as unverified until confirmed through internal channels.
  4. Revisit third-party access paths — particularly those used by managed service providers — with attention to logging, credential persistence, and whether one compromised MSP account could reach multiple endpoints.
  5. Train users against the specific lures, not generic "do not click" advice. Meeting invitations, PDF-themed messages, and fake update prompts each carry a different authority signal; training should name them explicitly.
  6. Alert on anomalous remote-access connections — unusual accounts, unusual hours, or endpoints that have no business being remotely managed.

The open question

Microsoft's advisory leaves attribution open, which suggests the company views the technique as broadly applicable rather than tied to one actor — an unnamed technique is one that may be reused, possibly by multiple groups, possibly with different follow-on payloads once an RMM foothold is established.

The detection gap the campaign exploits is not a signature gap. It is a visibility gap: benign software, used in unauthorized ways, in an environment that may never have asked what was already installed. Every whitelisted management agent on an endpoint is a potential future intrusion vector — and the sooner an organization can answer "what remote-access tools do we actually have running?", the sooner this class of technique loses its advantage.

Source: The Hacker News


Microsoft 已警告,威脅行為者正透過釣魚電郵散播 MSP360 遠端監控與管理(Remote Monitoring and Management,RMM)軟件的合法、已簽署安裝程式,其後再於其上部署第二個遠端存取工具 ScreenConnect。

據 The Hacker News 的報道,相關攻擊活動以會議邀請為主題的誘餌、PDF 內容、軟件更新提示及其他社會工程訊息來包裝安裝程式。Microsoft 表示,一旦執行,該合法的 MSP360 安裝程式——只是以具誤導性的檔案名稱分發——便會在受影響的電腦上建立遠端管理存取權限。

Microsoft 在安全通告中並未指名任何威脅行為者,亦未指出任何特定的受管服務供應商被用作初步入侵途徑。The Hacker News 將這批攻擊活動定位為一套可重複使用的步驟序列,而非某一個已識別組織所為。

攻擊鏈的運作方式

報道指,MSP360 安裝程式完全透過無害的軟件來建立初步的遠端管理存取權限。在該立足點已穩固建立之後,攻擊者再於其上安裝 ScreenConnect,令同一端點上多了一條獨立的遠端存取通道。

這兩個工具都是合法、已簽署的產品——正是那類透過正常渠道交付時,端點保護平台不會加以標記的軟件。以簽章為基礎的偵測手段,按其設計本來就不是為了質疑它們而構建的。

據報道所述,這種層疊部署看來是刻意安排的。只要防禦者移除其中一個工具,第二個工具便能令入侵得以持續。兩個工具產生的流量也與日常管理活動無異——遠端工作階段、管理代理程式、更新流量——因而容易融入受管環境的背景之中。實際效果是,偵測的問題由「這款軟件是否為惡意?」轉變為「這款軟件本來是否應安裝在這裡?」

為何受管服務供應商首當其衝

管理代理程式往往大批部署、以提升權限安裝,而且通常被預期會出現於端點之上。正是這份預期,令它們在這種模式下成為有效的入侵途徑。

根據報道所述的技術運作方式,受管服務供應商在這方面看來尤其暴露。任何一個受管端點上的一個 RMM 立足點,都有可能蔓延成跨客戶的事件;而重構第三方所管端點上的工具清單,難度遠高於審計企業自己有意批准的軟件。報道並未點名任何 MSP 為目標。

防禦者可以採取的行動

防禦者可參考下列行動;方向與 Microsoft 通告中的緩解措施及安全社群就 RMM 濫用問題的更廣泛指引一致:

  1. 徹底盤點所有已部署的 RMM 工具,包括由受管服務供應商安裝或透過企業交易而取得的第三方代理程式。凡不在已批准名單上的,一律應視為事件處理,而非接受風險。
  2. 監控安裝事件,而不只是偵測負載(payload)。以簽章為基礎的偵測手段,對此技術在結構上是盲目的。應用程式白名單、安裝時的遙測數據,以及針對異常安裝程式活動的警報,可以填補端點保護遺留的偵測缺口。
  3. 限制可安裝遠端管理工具的用戶身份,並視任何以電郵發出的軟件更新提示為未經核實,直至透過內部渠道確認。
  4. 重新檢視第三方存取途徑——尤其是受管服務供應商所使用的途徑——重點審視日誌記錄、憑證持久性,以及單一被入侵的 MSP 帳戶是否能夠接觸多個端點。
  5. 針對具體的誘餌訓練用戶,而非泛泛的「切勿點擊」忠告。會議邀請、以 PDF 為主題的訊息及假更新提示各自傳遞不同的權威信號;培訓內容應逐一明確點名。
  6. 就異常的遠端存取連線發出警報——包括不尋常的帳戶、非工作時段的活動,或是根本沒有理由被遠端管理的端點。

未有定論的問題

Microsoft 的通告刻意不作歸因,這意味著 Microsoft 視此技術為廣泛適用,而非只與某一個行為者相關——一項未被點名的技術,正是一項預期會被重複使用的技術,而且可能由多個組織採用,甚至在 RMM 立足點建立後,加裝不同的後續惡意程式。

該攻擊活動所利用的偵測缺口,並非簽章的缺口,而是可見度的缺口:無害的軟件被用於未經授權的方式,而所在環境可能從未就已安裝的內容問過正確的問題。端點上每一個已列入白名單的管理代理程式,都是一個潛在的未來入侵途徑——一家機構越早能回答「我們實際上正在運行哪些遠端存取工具?」,這一類技術便會越早失去其優勢。

資料來源:The Hacker News

新聞來源 / Original News Source