Microsoft has issued a warning about an active social engineering campaign in which threat actors distribute a legitimate MSP360 Remote Monitoring and Management (RMM) installer under deceptive file names and lures — fake meeting invitations, PDF-themed documents, and bogus software update prompts. Once a victim executes the installer, it establishes persistent remote management access on the host. The attackers then leverage that MSP360 foothold to deploy a second RMM tool, ConnectWise ScreenConnect, giving them redundant, layered remote access that blends into legitimate administrative tooling.
This is a textbook example of what we in the IR community have been tracking aggressively over the past 18 months: the weaponization of legitimate RMM software as a post-compromise and initial-access vector. Because MSP360 and ScreenConnect are signed, legitimate commercial products, traditional signature-based antivirus frequently ignores them entirely. EDR platforms that rely on known-bad hash matching will also stay quiet. The result is an intrusion that looks, at the binary level, like routine IT administration — until you examine the context of how and why the software landed on the endpoint.
If your organization does not have an explicit allowlist of approved RMM tools, with detection coverage for everything else, you are exposed to this campaign right now. This post breaks down the attack chain, gives you production-ready Sigma, KQL, and Velociraptor detections, and walks through containment and hardening steps.
Technical Analysis
What Is Being Abused
No software vulnerability is involved here — and that is precisely the point. There is no CVE to patch. The attackers are abusing the legitimate functionality of two commercial products:
- MSP360 (formerly CloudBerry) — a legitimate RMM and backup platform. The installer, when executed, silently (or near-silently) enrolls the endpoint into an attacker-controlled MSP360 management tenant, enabling remote command execution, file transfer, and scripting capabilities.
- ConnectWise ScreenConnect — a legitimate remote access tool that has been repeatedly abused by ransomware affiliates and initial access brokers. In this campaign, ScreenConnect is deployed as a second RMM after MSP360 access is established — the "dual-RMM" technique.
The dual-RMM pattern serves three attacker objectives:
- Redundancy — if defenders discover and remove one tool, the second maintains persistence.
- Evasion — different organizations allowlist different RMM vendors; two tools doubles the chance one slips past application control.
- Attribution confusion — blended legitimate tooling muddies the forensic timeline and makes the intrusion look like shadow IT rather than adversary activity.
Attack Chain (Defender's View)
- Delivery (TA0001 / T1566): Victim receives a socially engineered lure — a fake meeting invitation, a PDF-themed attachment or link, or a fake software update prompt. The payload is the genuine, digitally signed MSP360 installer renamed to match the lure theme (e.g.,
Meeting_Invite.exe,Invoice_Scan.exe,Adobe_Update.exe). - Execution (TA0002 / T1204.002): User executes the installer. MSP360 agent installs, registers a Windows service, and phones home to the attacker's MSP360 management console.
- Persistence (TA0003 / T1543.003): The MSP360 agent installs as a Windows service, surviving reboots and running with SYSTEM privileges.
- Command and Control (TA0011 / T1219): MSP360 agent maintains outbound TLS connectivity to vendor cloud infrastructure — traffic that bypasses most egress filtering because it is destined for a legitimate SaaS provider.
- Second-stage deployment (T1105): Using MSP360's remote execution capability, the attacker downloads and installs ScreenConnect (
ScreenConnect.ClientService.exe/ScreenConnect.WindowsClient.exe), establishing an independent second access channel. - Post-exploitation: From either RMM, the actor stages discovery, credential access, lateral movement, and — in campaigns of this type historically — data exfiltration or ransomware detonation.
Exploitation Status
Microsoft has confirmed active, in-the-wild distribution of the maliciously repackaged MSP360 installer via social engineering. This is not theoretical. There is no CISA KEV entry because no CVE exists — the abuse of legitimate RMM tooling is tracked as technique-level threat activity (MITRE ATT&CK T1219, Remote Access Software). Defenders should treat any unauthorized instance of MSP360 or ScreenConnect in their environment as a confirmed incident until proven otherwise.
Detection & Response
The detections below focus on high-fidelity behavioral signals: unauthorized RMM installation, suspicious parent-child process relationships, service creation, and the dual-RMM co-occurrence pattern that is the signature of this campaign. Tune the allowlist filters to reflect RMM products actually approved in your environment.
Sigma Rules
---
title: MSP360 RMM Agent Installation or Execution
description: Detects installation or execution of MSP360 (CloudBerry) RMM components. Any MSP360 presence should be validated against the organization's approved software inventory, as this tool is actively abused in social engineering campaigns to establish unauthorized remote access.
references:
- https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
- https://attack.mitre.org/techniques/T1219/
author: Security Arsenal
date: 2026/09/15
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|contains:
- '\\MSP360'
- '\\CloudBerry'
- '\\Remote Management'
selection_name:
Image|endswith:
- '\\MSP360.exe'
- '\\OnlineBackup.exe'
- '\\CloudBerryService.exe'
- '\\RemoteManagementService.exe'
selection_cmd:
CommandLine|contains:
- 'msp360'
- 'cloudberrylab'
condition: 1 of selection_*
falsepositives:
- Organizations that legitimately deploy MSP360 for managed backup or remote administration - allowlist approved deployment paths and installer hashes
level: high
---
title: ScreenConnect Client Service Installation
description: Detects installation of the ConnectWise ScreenConnect client service, including renamed instances. ScreenConnect is frequently deployed as a second-stage RMM by threat actors after initial access via another tool such as MSP360.
references:
- https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
- https://attack.mitre.org/techniques/T1543/003/
author: Security Arsenal
date: 2026/09/15
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_sc:
Image|endswith: '\\sc.exe'
CommandLine|contains:
- 'ScreenConnect'
- 'screenconnect'
selection_ps:
Image|endswith:
- '\\powershell.exe'
- '\\pwsh.exe'
CommandLine|contains:
- 'ScreenConnect'
- 'New-Service'
selection_service_binary:
CommandLine|contains:
- 'ScreenConnect.ClientService.exe'
- 'ScreenConnect.WindowsClient.exe'
condition: 1 of selection_*
falsepositives:
- Approved internal or MSP use of ScreenConnect - restrict to authorized deployment accounts and paths
level: high
---
title: Dual RMM Co-Occurrence - MSP360 Spawning ScreenConnect Deployment
description: Detects MSP360 agent processes spawning installers, script interpreters, or download commands consistent with second-stage RMM deployment. This parent-child relationship is a strong indicator of the dual-RMM intrusion pattern reported by Microsoft.
references:
- https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
- https://attack.mitre.org/techniques/T1105/
author: Security Arsenal
date: 2026/09/15
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|contains:
- '\\MSP360'
- '\\CloudBerry'
- '\\Remote Management'
selection_child:
Image|endswith:
- '\\powershell.exe'
- '\\pwsh.exe'
- '\\cmd.exe'
- '\\msiexec.exe'
- '\\curl.exe'
- '\\certutil.exe'
- '\\bitsadmin.exe'
- '\\wscript.exe'
- '\\cscript.exe'
condition: all of selection_*
falsepositives:
- Legitimate MSP360 remote scripting by an authorized administrator - validate against change records and approved admin accounts
level: critical
KQL — Microsoft Sentinel / Defender
This query hunts for the campaign's observable footprint: MSP360 process artifacts, ScreenConnect deployment, and the dual-RMM parent-child chain.
let RMM_MSP360 = dynamic(["MSP360.exe", "CloudBerryService.exe", "OnlineBackup.exe", "RemoteManagementService.exe"]);
let SuspiciousChildren = dynamic(["powershell.exe", "pwsh.exe", "cmd.exe", "msiexec.exe", "curl.exe", "certutil.exe", "bitsadmin.exe", "wscript.exe", "cscript.exe", "rundll32.exe"]);
// Hunt 1: MSP360 execution or installation artifacts
let msp360_events = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName in~ (RMM_MSP360)
or ProcessCommandLine has_any ("msp360", "cloudberrylab", "cloudberry")
or FolderPath has_any ("\\MSP360\\", "\\CloudBerry\\", "\\Remote Management\\")
| project TimeGenerated, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256;
// Hunt 2: ScreenConnect installation
let screenconnect_events = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName has_any ("ScreenConnect.ClientService.exe", "ScreenConnect.WindowsClient.exe")
or ProcessCommandLine has "screenconnect"
or FolderPath has "ScreenConnect"
| project TimeGenerated, DeviceName, AccountName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName;
// Hunt 3: Dual-RMM chain - MSP360 parent spawning deployment tooling
let dual_rmm_chain = DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where InitiatingProcessFolderPath has_any ("\\MSP360\\", "\\CloudBerry\\")
or InitiatingProcessFileName in~ (RMM_MSP360)
| where FileName in~ (SuspiciousChildren)
| project TimeGenerated, DeviceName, AccountName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, SHA256;
// Combine and surface devices with co-occurring RMM artifacts
union msp360_events, screenconnect_events, dual_rmm_chain
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), DistinctProcesses = dcount(FileName) by DeviceName
| where DistinctProcesses > 1 or EventCount > 0
| sort by LastSeen desc
Also hunt service installation telemetry (Event ID 7045 via SecurityEvent) for RMM service registration:
SecurityEvent
| where TimeGenerated > ago(30d)
| where EventID == 7045
| where ServiceName has_any ("MSP360", "CloudBerry", "ScreenConnect")
or ServiceFileName has_any ("MSP360", "CloudBerry", "ScreenConnect")
| project TimeGenerated, Computer, Account, ServiceName, ServiceFileName, ServiceType, ServiceStartType
| sort by TimeGenerated desc
Velociraptor VQL
Use this hunt artifact to sweep endpoints for unauthorized RMM artifacts — running processes, installed services, and on-disk binaries.
-- Hunt for unauthorized RMM artifacts: MSP360 and ScreenConnect
-- Targets running processes, services, and common install paths
LET processes = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)(msp360|cloudberry|screenconnect)'
OR Exe =~ '(?i)(msp360|cloudberry|screenconnect)'
OR CommandLine =~ '(?i)(msp360|cloudberrylab|screenconnect)'
LET services = SELECT Name, DisplayName, PathName, StartMode, State
FROM wmi(query="SELECT Name, DisplayName, PathName, StartMode, State FROM Win32_Service", namespace="root/cimv2")
WHERE Name =~ '(?i)(msp360|cloudberry|screenconnect)'
OR DisplayName =~ '(?i)(msp360|cloudberry|screenconnect)'
OR PathName =~ '(?i)(msp360|cloudberry|screenconnect)'
LET binaries = SELECT FullPath, Size, Mtime
FROM glob(globs=[
'C:/Program Files*/**/*MSP360*',
'C:/Program Files*/**/*CloudBerry*',
'C:/Program Files*/**/*ScreenConnect*',
'C:/ProgramData/**/ScreenConnect*',
'C:/Users/*/AppData/**/ScreenConnect*',
'C:/Users/*/Downloads/**/*MSP360*'
])
SELECT * FROM processes
UNION ALL
SELECT NULL AS Pid, DisplayName AS Name, PathName AS CommandLine, FullPath AS Exe, StartMode AS Username, Mtime AS CreateTime FROM (
SELECT NULL AS DisplayName, NULL AS PathName, NULL AS FullPath, NULL AS StartMode, NULL AS Mtime WHERE FALSE
)
Remediation Script
The following PowerShell script audits a Windows endpoint for unauthorized MSP360 and ScreenConnect artifacts, and optionally removes them. Run it in audit mode first (-Remediate:$false), review the output against your approved software inventory, then remediate confirmed unauthorized instances.
#Requires -RunAsAdministrator
# audit-and-remove-unauthorized-rmm.ps1
# Audits for and optionally removes unauthorized MSP360 / ScreenConnect RMM artifacts
# Usage: .\audit-and-remove-unauthorized-rmm.ps1 (audit only)
# .\audit-and-remove-unauthorized-rmm.ps1 -Remediate (audit + remove)
param(
[switch]$Remediate = $false
)
$RmmPatterns = 'MSP360|CloudBerry|ScreenConnect'
$findings = @()
Write-Host "[*] Auditing services..." -ForegroundColor Cyan
$services = Get-CimInstance Win32_Service | Where-Object {
$_.Name -match $RmmPatterns -or $_.DisplayName -match $RmmPatterns -or $_.PathName -match $RmmPatterns
}
foreach ($svc in $services) {
$findings += [pscustomobject]@{ Type='Service'; Name=$svc.Name; Path=$svc.PathName; State=$svc.State }
if ($Remediate) {
Write-Host "[-] Stopping and removing service: $($svc.Name)" -ForegroundColor Yellow
Stop-Service -Name $svc.Name -Force -ErrorAction SilentlyContinue
sc.exe delete $svc.Name | Out-Null
}
}
Write-Host "[*] Auditing running processes..." -ForegroundColor Cyan
$procs = Get-Process | Where-Object { $_.Name -match $RmmPatterns -or $_.Path -match $RmmPatterns }
foreach ($p in $procs) {
$findings += [pscustomobject]@{ Type='Process'; Name=$p.Name; Path=$p.Path; State='Running' }
if ($Remediate) {
Write-Host "[-] Terminating process: $($p.Name) (PID $($p.Id))" -ForegroundColor Yellow
Stop-Process -Id $p.Id -Force -ErrorAction SilentlyContinue
}
}
Write-Host "[*] Auditing scheduled tasks..." -ForegroundColor Cyan
$tasks = Get-ScheduledTask | Where-Object {
$_.TaskName -match $RmmPatterns -or ($_.Actions.Execute -match $RmmPatterns)
}
foreach ($t in $tasks) {
$findings += [pscustomobject]@{ Type='ScheduledTask'; Name=$t.TaskName; Path=$t.Actions.Execute; State=$t.State }
if ($Remediate) {
Unregister-ScheduledTask -TaskName $t.TaskName -Confirm:$false -ErrorAction SilentlyContinue
}
}
Write-Host "[*] Auditing installed programs..." -ForegroundColor Cyan
$uninstallPaths = @(
'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
$apps = Get-ItemProperty $uninstallPaths -ErrorAction SilentlyContinue |
Where-Object { $_.DisplayName -match $RmmPatterns }
foreach ($a in $apps) {
$findings += [pscustomobject]@{ Type='InstalledApp'; Name=$a.DisplayName; Path=$a.InstallLocation; State='Installed' }
if ($Remediate -and $a.UninstallString) {
Write-Host "[-] Uninstalling: $($a.DisplayName)" -ForegroundColor Yellow
# Review the uninstall string before executing in production
Invoke-Expression $a.UninstallString
}
}
Write-Host "[*] Auditing run keys for RMM persistence..." -ForegroundColor Cyan
$runKeys = @('HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run')
foreach ($rk in $runKeys) {
Get-ItemProperty $rk -ErrorAction SilentlyContinue | Get-Member -MemberType NoteProperty |
Where-Object { $_.Definition -match $RmmPatterns } | ForEach-Object {
$findings += [pscustomobject]@{ Type='RunKey'; Name=$_.Name; Path=$rk; State='Persistent' }
}
}
Write-Host "`n===== FINDINGS =====" -ForegroundColor Green
if ($findings.Count -eq 0) {
Write-Host "No MSP360/ScreenConnect artifacts found." -ForegroundColor Green
} else {
$findings | Format-Table -AutoSize
Write-Host "IMPORTANT: Validate each finding against your approved software inventory before removal." -ForegroundColor Red
Write-Host "Unauthorized RMM presence = treat as a confirmed incident. Preserve evidence before remediation." -ForegroundColor Red
}
Remediation
Because this campaign abuses legitimate software rather than a vulnerability, remediation is a policy-and-control exercise, not a patching exercise. Take the following steps immediately:
-
Establish an approved RMM allowlist — today. Enumerate every remote access tool legitimately used in your environment (by IT, your MSP, and your vendors). Everything outside that list is unauthorized by definition. Enforce this via application control (WDAC or AppLocker) blocking execution of non-approved RMM binaries and installers.
-
Hunt across the fleet. Run the KQL and VQL queries above across a minimum 30-day lookback. Any unauthorized MSP360 or ScreenConnect presence must be triaged as a confirmed intrusion, not a software hygiene issue — check for secondary payloads, credential access artifacts, and lateral movement before wiping the box.
-
Block at the email and web gateway. Filter or detonate executables disguised as meeting invitations, PDFs, and update prompts. Flag inbound messages with executable attachments or links to RMM vendor download domains from senders outside your approved MSP relationships.
-
Egress filtering. Where feasible, alert on outbound connections to RMM vendor cloud infrastructure (MSP360/CloudBerry and ScreenConnect relay domains) from endpoints that are not managed by an approved instance. Legitimate SaaS destinations mean you cannot blanket-block, but context-based alerting is achievable.
-
Service creation monitoring. Ensure Event ID 7045 (and Sysmon Event ID 6 if deployed) is collected and alerted on for any service installation matching RMM naming patterns, as shown in the KQL above.
-
User awareness targeting this lure set. Brief help desk and end users specifically on fake meeting-invite, PDF, and software-update lures delivering "installers." This campaign succeeds because the payload is signed and looks benign — users are the control point.
-
If compromise is confirmed: isolate the host, capture volatile data before removing the RMM agents (the dual-RMM pattern means a second access channel likely exists), review authentication logs for access during the RMM session windows, rotate credentials exposed to the host, and hunt laterally for the same tooling on adjacent systems.
There is no vendor patch and no CISA KEV deadline for this activity because no flaw exists in the products themselves. Your defense is visibility, allowlisting, and rapid response when unauthorized remote access tooling appears. Organizations with a managed SOC watching for exactly these behaviors detect this campaign at installation — not at ransomware detonation.
Related Resources
Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.