Situation
We want to be direct about a current issue affecting MSP360 RMM and Connect. Several antivirus products are flagging these applications as malicious because of revoked code-signing certificate.
This issue also affected our Backup which code-signing certificate has already been re-issued.
Background on the problem
Over recent months, attackers used social engineering to misuse our software. They renamed and rebranded the installer so it looked like familiar tools for online meetings, electronic signatures, and similar everyday applications. Users installed it voluntarily, giving the attackers full remote access to their machines.
Because the attackers used legitimate MSP360 software to gain access, our product appeared in the incident reports that followed. Those reports led antivirus vendors to flag our code-signing certificate which got revoked.
We identified and blocked close to 2000 fraudulent accounts through active monitoring and community reports. Once blocked, those accounts lose all ability to sign in, monitor, or manage any remote computer.
Mitigation steps already taken
We have made structural changes so this type of abuse is much harder to repeat.
New accounts must now pass a business verification review before they can perform any high-risk action. Until verification is complete, the following capabilities remain gated:
- Changing product branding
- Enabling remote management in MSP360 RMM (monitoring remains available)
- Enabling direct access in MSP360 Connect
We locked these specific capabilities behind verification because they were the ones that made the abuse pattern attractive.
We are also adding signature and antivirus checks for any software deployed through MSP360 RMM, so the deployment pipeline itself carries an extra layer of scrutiny.
We have adopted the Code of Conduct for responsible RMM and Remote Desktop vendors and published a dedicated abuse reporting channel. Reports can be submitted here:
https://www.msp360.com/trust-center/#report-form
Next steps
We have obtained a new code-signing certificate for the RMM and Connect products. This required a full company review by the certificate authority. Currently we are reconfiguring our pipelines to update the code-signing certificate.
We will notify you as soon as the newly signed versions are ready.


