Microsoft has warned of a phishing campaign in which emails posing as meeting invitations push recipients to install MSP360, a legitimate remote management tool. Once it is running, the attackers use it as a foothold and go on to install ConnectWise ScreenConnect as a second, more durable backdoor. The story was reported on 30 September, and it matters to UK small businesses because nothing in the attack looks like malware.
Why this works so well
MSP360 is real software, sold to IT support firms for managing backups and remote machines. Antivirus tools generally do not flag it, because on most networks it is perfectly legitimate. The attackers simply abuse it.
The lure is also ordinary. Everyone receives meeting invitations: a client wants a call, a supplier wants a demo, a recruiter wants a chat. A message that says “Join the meeting, you need to install our viewer first” does not feel unusual in a week full of video calls. The person clicks, runs the installer, and has handed over control of their computer.
From there the attacker can see the screen, move files and, in the worst case, move onto other machines. Many ransomware incidents begin exactly like this: quiet remote access first, encryption weeks later.
What to do this week
Agree a rule on installing software. Staff should never install a “meeting viewer” or “plugin” because an email said so. Genuine Teams, Zoom and Google Meet calls run in the browser or in an app you already have. If a link demands a new download, stop and ask.
Restrict who can install software. If every employee has local admin rights, one click is enough. Remove them wherever you can. In Microsoft 365 Business Premium, tools such as Intune and Defender for Business can block unapproved applications for a modest monthly cost.
Know which remote tools you use, and block the rest. Make a short list of the remote access software your IT provider actually uses. Anything else, including MSP360, ScreenConnect, AnyDesk or TeamViewer, appearing on a machine without your say-so is a red flag. Ask your provider to alert on unexpected installs.
Check what is already there. Ask your IT support to audit for remote management software across your devices. If you find something nobody can explain, treat it as an incident rather than clearing it up quietly.
If someone has already clicked
Act fast. Disconnect the computer from the network, do not switch it off if you can avoid it, and call your IT provider. Change the passwords the user typed or saved on that machine, using a different, clean device. Review recent sign-in activity on their Microsoft 365 or Google account for logins you do not recognise.
If you are not sure what is normal on your network, a service like KeepSafe tracks live cyber incidents so you can see which techniques are being used against UK businesses at the moment, and it is a useful way to brief your team without sending them a technical report.
It also helps to write your response plan down before you need it. Who gets called, who decides to isolate a machine, and who talks to customers if data may be affected? Ten minutes now saves hours of panic later.
The takeaway
Attackers have worked out that trusted software gets past defences that were built to catch bad software. Training staff to distrust files is no longer enough; they need to distrust requests to install anything at all.
Send one short message to your team today: “If an email asks you to download something to join a meeting, forward it to us first.” It costs nothing and closes the door this campaign relies on.