Fake Meeting Invites Are Now Delivering Real Remote-Control Software

Microsoft says attackers are skipping the malware and installing legitimate MSP360 and ScreenConnect on victim machines, giving themselves a hands-on-keyboard foothold that looks like normal IT admin work.

ThreatVectr Newsdesk· Editor: Lee Brown· 4 min read
Full-frame photoreal editorial image of a generic laptop screen at night showing a plain calendar meeting invitation with a paperclip attachment icon, soft blue
Share

Key points

  • Microsoft Defender Experts saw phishing emails in July 2026 that trick staff into installing a real copy of MSP360, a commercial remote-management tool, disguised as a meeting invite or PDF.
  • Once MSP360 is running, the attackers use it to quietly install a second remote-control program, ConnectWise ScreenConnect, so they still have a way in if one gets removed.
  • Microsoft says ScreenConnect itself wasn't hacked; the criminals are abusing legitimate software they obtained normally.
  • The technique is a version of what defenders call "living off the land," using tools that IT teams already trust so alarms don't fire.
  • Threat Vectr's own tracking of criminal leak sites shows a steady rise through 2026 in intrusions that begin with a booby-trapped installer rather than a software flaw.

Microsoft has flagged a phishing wave that does something almost boring on the surface: it installs real, paid-for IT software on the victim's PC. That is the point.

Microsoft Defender Experts said the campaigns began in July 2026 and hit organisations across several industries. The lure varies: a meeting invitation, a PDF, or a fake software update nag. Click the file and you install MSP360, a legitimate remote monitoring and management tool, meaning software that IT departments use to log into staff computers from afar to fix things.

Only here, the person on the other end isn't IT.

How does the attack actually work?

The victim runs what looks like a normal file and unknowingly gives an outsider a remote-control session on their machine. Microsoft says the MSP360 installer is genuine but carries a misleading file name to slip past suspicion.

Once the attackers have that first way in, they use it to pull down and install a second remote-control tool, ConnectWise ScreenConnect. Now they have two doors into the same building. Kick one shut and the other still opens. Microsoft was careful to note it didn't see any hacking of ScreenConnect itself. The criminals are simply buying or obtaining the software the way any small IT shop would.

After that, it's the usual post-break-in shopping list: hunting for saved passwords, poking around file shares, staging the next move.

Why is this hard to catch?

Nothing on the machine is technically malware. MSP360 and ScreenConnect are trusted products sold to IT providers around the world. Antivirus won't flag them. A network monitor sees remote-management traffic and shrugs, because remote-management traffic is what a real help desk generates all day.

Think of it as a burglar wearing a courier uniform. The uniform is real, the clipboard is real, and what's fake is the reason they're at your door.

This fits a pattern we've been tracking since our 1 September report on attackers who enrolled more than 450 computers into Faronics Deploy before pivoting to ScreenConnect. Ransomware crews and access brokers increasingly prefer commercial remote-support tools over custom backdoors. Our own review of criminal leak-site posts this year shows a growing share of listed victims where the initial foothold, when described, involved a signed installer of a legitimate RMM product rather than an exploited software flaw.

My read: this is the boring endgame of a decade of endpoint-security investment. Defenders got good enough at spotting weird binaries that attackers stopped shipping them. Whitelisting MSP360 because "the IT team uses it" is now a security decision, not a convenience one.

What should ordinary staff do?

Two practical habits. First, if a meeting invite or PDF asks you to install anything, call the sender on a number you already have. Second, if a piece of software you didn't ask for appears in your system tray, especially one with names like MSP360 or ScreenConnect, tell your IT team the same day. That icon is the whole attack.

Common questions

Is MSP360 or ScreenConnect unsafe to use?

No. Both are legitimate products used by IT providers worldwide. The problem here is criminals installing them on machines that shouldn't have them, not a flaw in the software.

How would I know if this happened to me?

Look for remote-support software you didn't install, unexpected mouse movement or windows opening on their own, and any prompt asking you to "approve" a remote session you never requested.

© 2026 Threat Vectr