Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Hackers are using familiar Zoom setup files and PDF reader downloads to place remote-control software on business computers. The campaign turns ordinary workplace prompts into a path for outsiders to take over a device.

The phishing emails use meeting invitations, document requests, software updates, RSVP cards, job offers and delivery notices. Victims who follow the links reach pages that imitate document portals, Adobe downloads, Zoom installation pages, or collaboration services.

Microsoft analysts identified the activity in July 2026 across organizations in several industries. The operation delivers a real, digitally signed MSP360 Remote Monitoring and Management installer, but disguises it with names designed to look safe.

Microsoft said in a report shared with Cyber Security News (CSN) that it has not tied the campaign to a named group. The finding shows why trusted administration tools can be just as dangerous as traditional malware when an attacker controls their installation.

Hackers Disguise Remote Access Tools as Zoom and PDF Installers

The initial file is MSP360 RMM version 2.5.0.67, presented as a meeting app, PDF utility, invitation, or business document. The disguises exploit the same misplaced trust as signed workplace application lures that abuse familiar names to lower suspicion.

After a victim runs the file and approves the Windows administrator prompt, it installs MSP360 services and adds automatic startup entries. It also creates a firewall rule allowing inbound UDP traffic to the RMM agent on port 48678, giving the software the access it needs to communicate.

The attackers did not exploit a flaw in the remote-control programs. Instead, they used legitimate tools as intended, except the remote session belonged to them. That distinction can make the intrusion blend into normal technical-support activity and complicate quick detection.

Not every attempt succeeded. Where users denied or abandoned the administrator approval prompt, installation stopped before the remote-management components were fully deployed.

Attack chain (Source - Microsoft)
Attack chain (Source – Microsoft)

Microsoft also saw separate July activity using another legitimate deployment agent to install ScreenConnect, showing that the approach was not limited to MSP360.

The delivery infrastructure changes frequently. Links have sent users to attacker-controlled sites, compromised websites, and cloud-hosted locations on Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.

This rotating approach echoes weaponized PDF RMM attacks, where a convincing document is only the first step toward a remote-access installation.

Second Channel Extends Control

Once MSP360 is active, its agent launches PowerShell to download an installation package and silently install a ConnectWise ScreenConnect client. That creates a second independent route into the computer, so removing one remote tool may not immediately cut off the intruder.

The ScreenConnect service then transfers and runs follow-on utilities from temporary folders in the user’s Documents or OneDrive Documents directory.

Researchers observed tools associated with password theft, browser-data collection, hiding windows or cursors, and launching further files, raising the risk of account compromise and wider network access.

This layered setup gives operators persistence, file transfer capability, and remote command execution while using software many IT teams recognize.

It reflects the same operational problem seen in the SMOKE#SCREEN remote-control campaign, where fake updates turn approved-style support software into an attacker foothold.

Organizations should maintain an inventory of approved remote-management applications and block unapproved instances, including by publisher certificate where appropriate.

They should require multi-factor authentication for sanctioned tools, keep cloud-based endpoint protection enabled, and investigate any unexpected RMM installation before it becomes a durable connection.

Security teams should also hunt for the listed installer hash, new MSP360 or ScreenConnect services, PowerShell started by the remote agent, and silent Windows Installer activity.

If an unauthorized deployment is found, passwords for accounts used to install the services should be reset, with deeper investigation when system-level credentials were involved.

Microsoft also recommends blocking or auditing process creation through PsExec and Windows Management Instrumentation, while checking for compatibility problems on some servers.

These controls target ways attackers can move between systems after gaining their first foothold. Email filters reduce chances that users reach deceptive download pages.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 108ef7e628d7a20bd6241a5b57149e27a6061f467123eb64061975559f8f73dc Legitimate MSP360 RMM v2.5.0.67 installer distributed under deceptive filenames; the sample was signed with a certificate that has since been revoked
SHA-1 f34330d4c6e0aa978dc3af40360c14b31ad51127 MSP360 RMM installer hash observed in the campaign
SHA-256 f094b8263471c7b76dbed03d420736449920368fa0eca2ed6b1aea2645138d97
857c2f283de799faa74b56e862c0a9f96e67aa1b4fa4a9e46395098365b99de3
6a89de024ca62536de6f5fc10e49896bb1ac330ca39dce30203afdcc45ae237e
4188c6588f3dcda881c3f2d12df580051179a999f040b799af506edeb3211a26
Legitimate MSP360 RMM Agent Service samples observed during the campaign
Domain adswre[.]cfd
trews[.]cfd
swedcorry[.]stefneyv[.]com
ojsuyw[.]niyari[.]org
bunstar[.]harej[.]si
adsaw[.]cfd
sdfghj[.]rd-team[.]ru
Domains contacted by ScreenConnect clients during observed malicious sessions
SHA-256 ceb3f7fe9a618ff29a21b126383c23900fad58d6ae2b5552d7e306e4b6acf4b0
02f2ce03a2650f17bfe6e8744eebbf58522016cbdb92af8f2217b5dd4a1ad550
499d07894f730fb685ee3cbfc1a933e0da93750c1ed25a49b2eb9c32adef156a
d49cc01641c3045bf3119f9d71e7ffd29bfce32ca4b27cc96340716ed4d41cdc
67c979dc13961b09f24f85a801e4c918420adca6117c92efbeeeaa68a6344f55
6cc665057c4a4fe42a309afd3a7fa96cf1af126e9c6e08e56df5105e05378bcc
dd434f3ffcafeda538d43226665115ba136ad0fdb43dad8536e1368ca9a17b64
40f8e774e1e7a484b78c7ae4336bc47aa9cab20dc8e1e67d89838e807975f9b1
3ff5e49fd2f2bd0758467763c44d69e781b7460af84a6e3966e2621bc5bf7096
374c4934b14a1151ea68847c8627c3f1c0b878f4e673bda3f15e4388dfde0187
bc8b1b0c80512ba0e8ffccfee5b507df16a3355db1143c3ba81ef42dac1baa6c
c2c004a56de2a99f5b06ceb58d8a4b371fb60fd66ff5936786fe8d8037ead208
5bf8cf29ac6803e7269b045dea48003af7cfe48bedfc081b57ff9e86cb08971b
19035c8e2520fb70b3e2ec5338c14311b88a26cc1fb8304a01494260b6b55af1
d232d82e410de12702a67c58acf927304ee42f3e6d81a9d71eca99f9052126db
d3cb7ded277b49be06e6a1860f7c7e913e252802e9d32453a185e24797bf53ef
e31e5da7c58a7e8f89f9629f095edd7d741a1fb0b85fcb39f3818dbd9497b1e3
1a534d04bf30894d20764e91f7e94e0a73f060f0abacc9feeedba427995c83a8
77fb0e75f4396cb57bbbd28f6dc5310369a87abec9e2acc457aa99a0063ed27a
fc96a04c615847f0fb1391f04d9d1aac7f78ddfb7d459168df0a4172b98354e2
06ad69b9bebad3cc75b594cc5bb1ca0035ea22bb8a683002ca051d948566426b
a93c946c237b981189d2668d938a9d4d1d9681757e48dae8d9d65ed25b5da657
529543b4fe6a4c21d28be56dbf92fcac91d8df808d8518b4275c973fa547ad63
ccea4e1acc51ac43ba9da76ada00e7e308cc33d9c5c264dff82d1be83e957b88
a03c84ae9e569c04fdd271277f508bba5a299d53c3c0efe0819338d178fe1c5b
Utilities transferred or executed through ScreenConnect sessions during post-compromise activity
File name VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe
ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe
PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe
RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe
SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe
Observed deceptive MSP360 installer filenames
File name ClientSetup.msi
WindVerify.exe
WindowsUpdate.exe
WindowsSecurity_PIN.exe
WindowsSecurity_Password.exe
WindowsPassKey.exe
SCHider.exe
PIN.exe
phonepc.exe
DefenderDT.exe
DefenderControl.exe
phonelinkupdate.exe
PhoneLinkPrompt.exe
Passwords.EXE
OpenCamera.exe
open_phone_link.exe
MouseHiderGUI.exe
HideUL.exe
HideMouseApp.dll
HideMouse.exe
HideFromControlPanel.exe
HideCursor.exe
BannerHider.exe
WebBrowserBookmarksView.exe
WebBrowserPassView.exe
ScreenConnect installer and utilities observed during post-compromise activity

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Hackers Disguise Remote Access Tools as Zoom and PDF Installers to Take Over PCs appeared first on Cyber Security News.