Most teams still treat a phishing click as a malware event. Block the hash, reset the password, close the ticket. Microsoft’s latest write-up should wreck that habit. Researchers watched campaigns abuse MSP360 remote monitoring software to deploy ScreenConnect, then keep both remote-access channels alive for whatever came next. Your cybersecurity stack already trusts that class of tool. It rides through the firewall as support traffic. Threat-protection products often score it as admin software. The interesting part of this week is the second console, sitting there with a signed installer and a policy exception you signed last year.
Your cybersecurity program still treats RMM as furniture
Remote monitoring and management tools exist because you asked for them. MSPs need a way into customer estates. Internal IT wants a supported path onto a laptop when the VPN client is sulking. That operational need hardens into a standing exception: these binaries are known, these ports are documented, these vendors show up on the approved list. Attackers read that list too.
Microsoft’s observed phishing rode a real MSP360 installer, then added ScreenConnect, then left both paths intact. Redundant remote access is a feature if you are the operator. It is a feature if you are the intruder as well. You can yank one agent in a panic and still have a live session on the other. Persistence arrives with a helpdesk EULA.
Look at how your controls actually behave. Application allowlisting loves signed, widely deployed IT software. Egress policies make room for ScreenConnect and its cousins because someone filed a ticket in 2024. Your SOC’s threat detection is tuned for odd processes, packed loaders, and command lines that look like crime. A legitimate RMM agent checking in looks like Tuesday. Defense in depth only works when each layer disagrees with the others. Here they all nod along.
This is a bad look for any program that still measures phishing success by catching the attachment. The attachment is optional. The user installs support software. The installer is real. The callback is real. Your change ticket from last spring already blessed the callback.

If you run an MSP, or you are a customer of one, assume the attacker wanted two consoles. Hunt for RMM products you do not stock. Hunt for a second instance of the one you do stock. Hunt for ScreenConnect and the rest of the usual unattended-access pack on hosts that should only have your standard agent. Inventory beats vibes. Signed still needs an owner in your inventory.
The second console is the campaign
Follow-on activity needs a door that survives the first cleanup. Credential resets leave a remote-access service running when that service authenticates as itself. Reimaging a laptop kills it, if you catch the right laptop. Catching it means you treat extra RMM as a severity-one identity issue.
Star Blizzard’s latest work, which Microsoft tracks as RedFlick, is the other half of the same week. Since January 2026 the Russian state actor has been grinding on phishing volume, hijacked website accounts, and a delivery trick built to slide past controls that flag obvious malware loaders. Different operator, different motive. Same bet: if the path into the endpoint looks like normal work, your stack will hesitate. State groups invest in delivery hygiene. Criminals invest in living off the helpdesk. You should assume both keep going.
An agent can open the door without a click
You don’t even need a phish for a privileged helper to act in your name. Malwarebytes reported that Meta’s Muse, chatting with a Facebook Marketplace buyer, shared a seller’s home address and lined up a pickup. The seller was not in that conversation. Software allowed to negotiate, share location, and finish a workflow will finish it. Users will not get a prompt for every side effect. If you would refuse a contractor who handed out office addresses from a chat window, refuse an assistant with that power over production data.

The same “it is ours, so it is fine” reflex is about to hit Windows laptops again. Microsoft made WSL containers generally available, and administrators can switch the feature off or pin where images come from. Developers will want it. A blessed Linux runtime on a corporate Windows box that already has an RMM agent is a gift. Skip those Intune controls and you add another execution path that looks like engineering.
Treat every remote agent like a privileged identity
Here is the unglamorous work. None of it requires a particular vendor. All of it assumes you already have some mix of EDR, email filtering, and a firewall, and that those tools have been trained to ignore your own remote-access stack.
- Inventory the agents today. Dump every RMM, remote-control, and unattended-access binary in the estate. Compare that list to procurement and to your MSP contract. Anything extra is an incident, including a second copy of your standard product with a different tenant ID or installer source.
- Pull the callbacks. Export about 30 days of outbound connections to known RMM cloud endpoints and self-hosted relay URLs. You want first-seen hosts, off-hours check-ins, and users who are not supposed to have a console. Hand that to incident response the same day. Do not park it in a hygiene backlog.
- Freeze boutique installs. Email and browser controls should block the common installer names and vendor download portals except from a managed software pipeline. If helpdesk needs a tool, they get it from you, hashed and wrapped, the way you ship the VPN client.
- Harden the consoles. Put RMM admin portals behind phishing-resistant MFA, tight source IP rules, and lockouts that still work when the noise is brute-force. The endpoint agent is only half the problem. The console password is the other half. Short sessions and device binding belong in the same security hardening pass.
- Prove dual-agent detection. Alert on RMM process launch from user-writable paths, unexpected parents such as Office or a browser, and two remote-access products on one host. Then fire a test. A rule that has never seen a dual-agent box is theater.
- Close the developer runtime the same way. Fold WSL containers into the allow/deny decision. Turn the feature off where you do not need it. Limit image sources where you do. That is cyber security as configuration, sitting next to the RMM exception you already regret.

Do that, and you still need a playbook for when the extra agent is already there. Isolate the host. Revoke the RMM tenant sessions and the user’s SSO token. Rotate local and cached credentials. Check for a third tool, because operators who like redundant access like it a lot. Then read your MSP contract and ask who else has a console into you.
Frequently Asked Questions
- Why would a phish install genuine helpdesk software?
- Real RMM binaries are signed, documented, and already permitted on a lot of networks. They give the operator a supported remote desktop, file transfer, and persistence that survives a password reset. Your threat-protection stack is much more likely to argue with a custom loader than with ScreenConnect.
- Should we ban every remote monitoring tool?
- Most shops cannot. MSPs and internal support still need a supported path onto endpoints. Ban the long tail you do not pay for, pin the one product you do pay for to a managed installer, and watch for a second agent the way you watch for a second admin account.
- What changes in incident response after a dual-RMM find?
- Scope the host as compromised until both agents, both tenants, and any extra unattended-access tool are gone. Revoke console sessions, rotate local secrets, and check neighboring machines for the same installer. The phishing mail is the opening scene. The live remote session is the incident.
Sources
- Phishing Abuses RMM Tools for Persistent Access
- Star Blizzard refines phishing and malware delivery with the RedFlick technique
- Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home
- WSL containers are generally available on Windows
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
