Menu
Blog Articles
Read MSP360’s latest news and expert articles about MSP business and technology

Code Signing Certificate Update: RMM and Connect

Code Signing Certificate Update: RMM and Connect

Situation

We want to be direct about a current issue affecting MSP360 RMM and Connect. Several antivirus products are flagging these applications as malicious because of revoked code-signing certificate.

This issue also affected our Backup which code-signing certificate has already been re-issued.

Background on the problem

Over recent months, attackers used social engineering to misuse our software. They renamed and rebranded the installer so it appeared to be familiar everyday software. Users installed it voluntarily, giving the attackers full remote access to their machines.

Because the attackers used legitimate MSP360 software to gain access, our product appeared in the incident reports that followed, and antivirus vendors began flagging our software.

We identified and blocked close to 2000 fraudulent accounts through active monitoring and community reports. Once blocked, those accounts lose all ability to sign in, monitor, or manage any remote computer.

Mitigation steps already taken

We have strengthened account verification, monitoring, and enforcement to make this type of misuse harder and improve our response when abuse is identified.

Account monitoring and enforcement

We investigate reports from affected users and IT administrators, alongside findings from our own monitoring, and block accounts associated with abuse. Blocked accounts can no longer sign in to MSP360 or use the platform to monitor or manage remote computers.

On May 12, 2026, we established a daily security review process to identify suspicious account activity and take action against accounts linked to misuse. These reviews supplement reports received from the community.

Account blocking stops access through MSP360. It should not be treated as confirmation that an affected device is free of other unauthorized software.

Stronger registration safeguards

On May 19, 2026, we added protection against automated account registration to our product signup process. These safeguards help reduce automated creation of accounts that could be used for abuse.

Business verification before higher-risk capabilities are enabled

On August 4, 2026, we introduced mandatory business verification before new accounts can use the following capabilities:

  • Customize installer branding
  • Perform remote-management operations in MSP360 RMM. Monitoring remains available before verification
  • Enable direct access in MSP360 Connect
  • Execute pre- and post-action scripts in MSP360 Backup

These restrictions require accounts to complete business verification before accessing capabilities that could otherwise be misused to disguise an installer or execute actions on remote computers.

Public reporting and vendor accountability

We have adopted the Code of Conduct for responsible RMM and Remote Desktop vendors that sets out our approach to account verification, abuse monitoring, reporting, and cooperation with the wider security community.
We also maintain a dedicated reporting channel through the MSP360 Trust & Safety Center. Anyone who suspects that MSP360 software has been used in a scam, unauthorized remote-access attempt, or other abusive activity can submit a report directly to our team. Reports are reviewed and investigated.

Current Status

We have obtained a new code-signing certificate for the RMM and Connect products. This required a full company review by the certificate authority. We have reconfigured our pipelines to use the new code-signing certificate.

This article was published on August 14, 2026 and updated on September 22, 2026

MSP360 Trust & Safety Center
Report scams, unauthorized remote access, or other misuse. Every submission is reviewed by our team.
CTA
trust-and-safety-center-cta1