Threat Intelligence

Fake Meeting Invites Used to Plant Dual Remote-Access Tools on Business PCs

The Hacker News · 1 Oct 2026
Key Takeaway Be cautious of unexpected meeting invites or software update prompts, and ensure your IT provider monitors for unauthorised installations of remote-access tools on company devices.

Microsoft has warned of phishing campaigns disguising a legitimate remote monitoring and management (RMM) tool, MSP360, as meeting invitations, PDF attachments, or software update prompts. When opened, the installer is digitally signed and appears genuine, but it quietly grants attackers remote access to the victim's device under the cover of trusted administrative software.

Once installed, MSP360 is used to run further commands that install a second remote-access tool, ConnectWise ScreenConnect, giving attackers a backup channel into the compromised computer. The malicious installer also adjusts system settings, including creating background services, registry entries so the software launches automatically, and firewall changes to allow hidden network traffic. This combination of two remote-access tools lets attackers blend in with normal IT administration activity, making the intrusion harder to detect, while they gather credentials and deploy further tools. Microsoft has not yet linked this campaign to a specific known attacker group.

Because the software involved is legitimate and commonly used by IT providers, traditional antivirus tools may not flag it as malicious, making user awareness and monitoring of unexpected installations especially important.

phishing RMM software remote access threats

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.