Threat in Practice

How a fake meeting invite can lead to remote access

Microsoft observed phishing that persuaded people to run legitimate remote-management software disguised as meeting or document downloads. Here is a low-cost way for a small team to check its own remote-support arrangements.

Published October 1, 2026 · Sources reviewed October 1, 2026

These instructions are source-reviewed, not lab-tested by Purposeful Security. Check the original sources and adapt the steps to your environment.

What happened

In research published September 29, 2026, Microsoft described phishing campaigns it observed in July 2026. The lures included meeting invitations, PDF-themed downloads, and software update prompts. People downloaded and ran a legitimate MSP360 RMM installer under a deceptive filename. When installation succeeded, it established remote management access. Microsoft then observed it being used to install ConnectWise ScreenConnect as a second remote-access channel.

Where the team can interrupt the chain
  1. Step 1

    Meeting or document lure

    A message or web page presents a download as normal business work.

  2. Step 2 · Your decision point

    Unexpected install prompt

    Stop and verify through a known contact route before running the file or approving an unexpected Windows permission prompt.

  3. Step 3 · If installation succeeds

    Remote-support access

    In the reported successful sequence, the tool enabled access and was used to install a second remote client.

This is a simplified explanation of Microsoft's observed sequence, not a claim that every suspicious download completes these steps.

Microsoft did not observe exploitation of ScreenConnect itself. The attacker abused legitimate software. A publisher name or digital signature cannot tell you whether your team approved a particular installation. Microsoft reported activity across multiple industries but did not provide a small-business victim count.

Could this affect your team?

This is relevant to teams with Windows computers whose users may run a downloaded installer. It also matters when an outside IT provider uses remote support: an unfamiliar entry may be an approved tool. Do not remove software based on its name alone. Confirm who installed it, why it is needed, and which computers should have it.

Fictional example

An office manager follows a plausible meeting invitation and is told to install a new meeting client. They run the downloaded file, and Windows asks for permission to make changes. If they approve the unexpected installer, a remote-support agent could be installed. This illustrates the decision point; it is not a customer story or a Purposeful Security lab result.

A no-new-product check for this week

  1. List the remote tools you approve. Ask your IT provider or support lead for product names, which devices should have them, and a known contact route to verify a support request. Keep the list with your asset inventory. A product name does not identify whose remote-support account controls an installation.
  2. Spot-check Windows computers. On Windows 11, open Start → Settings → Apps → Installed apps. Look for remote-support and management software, including MSP360 RMM and ScreenConnect, then compare with your approved list. Record the device, app name, and who confirmed its purpose. Begin with finance, administrator, and IT-support computers. This built-in screen is not a complete hunt: it checks installed apps on the computers you inspect, not every device or every form of remote access. No visible entry does not prove a computer is clean, and a visible entry does not prove compromise. Microsoft's installed-app instructions
  3. Set a rule for surprise installers. Staff should decline and report unexpected requests to install meeting, PDF, or support software from a message or web page. Confirm unusual requests using a contact route already known to the team. Use standard user accounts for daily work where practical, and an approved administrator route for legitimate installs. A Windows permission prompt asks whether to allow a change; it does not certify the download as safe. Microsoft on User Account Control

If you find an unexplained tool

Treat it as a possible incident, not proof of one. Use a known contact route to ask your IT provider or device owner whether the installation was approved. Record the device, time, app or filename, and what the user remembers; avoid deleting useful evidence. Report an attempted install even if a Windows permission prompt was denied; Microsoft observed some installs stop at that point.

If an installation is unapproved or still unexplained, use your incident-response plan for containment and investigation. Have a qualified administrator check for a second remote-access tool and identify any account used to approve the installation. Microsoft recommends resetting passwords for accounts used to install unapproved RMM services. The administrator should decide when to disconnect the computer or remove software; abrupt removal can interrupt legitimate support and may leave follow-on access in place.

How to verify the improvement

You should have an approved remote-tool list, an owner for each unexplained entry, and a known route for checking unusual support requests. Compare the list with the computers you examined and record each resolution. A spot-check cannot certify that every device was examined or that no malicious access occurred.

Microsoft also recommends MFA for approved RMM tools and application controls to restrict unapproved software. These are optional follow-up controls whose availability and rollout requirements depend on your tools, Windows editions, management setup, and licenses. Test any block with your IT provider before applying it broadly.

Original sources

The scenario above is fictional. No installer, Windows check, containment step, or recovery procedure was lab-tested for this article. How Purposeful Security prepares guidance