Skip to content
Helpdesk & Ticketing

Fake Zoom and Adobe Installers Now Drop Real RMM Tools: One Helpdesk Rule That Helps

Microsoft reported phishing that installs a genuine, signed MSP360 RMM agent disguised as Zoom or Adobe, then adds ScreenConnect. Five helpdesk changes that close the gap.

H
Hamze Zare Nasiri
October 5, 2026
Fake Zoom and Adobe Installers Now Drop Real RMM Tools: One Helpdesk Rule That Helps

On 29 September 2026 Microsoft's security blog described a phishing campaign with an unusual payload. Microsoft Defender Experts saw it in July 2026: the victim does not get malware in the usual sense. They get a real, digitally signed copy of the MSP360 remote monitoring and management (RMM) agent, version 2.5.0.67, renamed to look like a Zoom client, an Adobe Acrobat update or a meeting invitation.

Once the user approves the Windows UAC prompt, the agent installs as a service. According to Microsoft, the attackers then used it to run PowerShell, download ConnectWise ScreenConnect and install it silently, which gave them a second remote-access channel. The same pattern showed up with Faronics Deploy. Microsoft found no exploit in either product. The tools did exactly what they were built to do.

Why this gets past the usual checks

The installer is signed by a real vendor, so it does not look like malware to a user or to a basic scanner. The lures are ordinary office traffic. Microsoft lists meeting requests, Zoom and Google Meet install prompts, PDF reader updates, RSVP e-cards, job offers, signature requests and parcel notices. The files were hosted on Amazon S3, Cloudflare R2, Dropbox, GitLab and Supabase, so blocking one domain does little.

The weak point is a habit, not a product. In most offices staff install meeting clients and PDF readers themselves whenever a link asks them to. That habit is what this campaign uses. It is the same lesson as phishing that steals the session instead of the password: the attacker borrows a normal workflow.

One rule for the helpdesk: software arrives through a ticket

Microsoft's own advice is technical: keep a list of approved RMM tools, block unapproved ones with Application Control or AppLocker publisher rules, and reset the passwords of any account that installed an unapproved agent. Those steps belong to the endpoint team. The helpdesk can close the gap from the other side with five small changes:

  1. Name your one remote-access tool. Put it in the knowledge base in a single sentence: "IT only connects with X, and only on a ticket you opened." Anything else asking for remote access is suspect by definition.
  2. Make software requests fast. If a "Zoom client" request takes three days, people will click the email link. Give meeting and PDF tools a same-day target and track it.
  3. Add a "suspicious email or install prompt" request type. It should take under a minute to file and land at high priority. A report that arrives before anyone clicks is cheaper than any cleanup.
  4. Log every unapproved agent you find as a ticket. Record the machine, the account that installed it, and the password reset. Microsoft's guidance is to reset that account's password and look further if a system account was used.
  5. Give the team something concrete to check. In Microsoft's write-up the agent sat in C:\Program Files\RMM Agent\, ran as RMM.Agent.exe and RMM.Agent.Launcher.exe, and opened an inbound UDP firewall rule on port 48678. A ScreenConnect service that IT never deployed is the second sign.

None of this needs a new tool. It needs request types with owners and deadlines, which is what any helpdesk worth choosing already does.

Where FanDesk fits

FanDesk is Fanpino's helpdesk. The five changes above map to plain configuration: a "Software request" category with its own SLA, a high-priority "Suspicious email or prompt" category, a knowledge base article that names the approved remote-access tool, and reports that show how long software requests actually wait. If software requests stop waiting, fewer people install what an email hands them. See FanDesk.

FAQ

What did Microsoft report on 29 September 2026?

Phishing campaigns that delivered a renamed but genuine MSP360 RMM installer through meeting, document and update lures, then used it to install ScreenConnect as a second remote-access channel.

Is MSP360 or ScreenConnect vulnerable?

No. Microsoft found no exploitation of either product. The attackers used legitimate software, and the signing certificate of that installer has since been revoked.

Can antivirus catch a signed RMM installer?

Not reliably, because the file is legitimate. Microsoft recommends allow-listing approved RMM tools and blocking the rest by publisher or certificate.

What can a helpdesk do that endpoint controls cannot?

Make the safe path faster than the risky one: quick software requests, one named remote-access tool, and a one-minute way to report a suspicious install prompt.

FanDesk helpdesk

Request categories with their own SLA, a knowledge base, and reports that show where requests wait.

See FanDesk

Share This Article