#MSP360RMM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns #CyberAttacks #Microsoft #MSP360RMM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns
 Microsoft has warned of a new wave of phishing campaigns that abuse the legitimate MSP360 Remote Monitoring and Management (RMM) software to establish persistent remote access on victim devices. Once this foothold is secured, attackers deploy a second RMM tool, ConnectWise ScreenConnect, creating a redundant channel for control and further malicious activity. This dual-RMM technique enables threat actors to blend into normal IT operations while carrying out credential theft and data exfiltration with reduced risk of detection.  The attack chain, observed by Microsoft in July 2026, begins with phishing emails disguised as meeting invites, PDF-related lures, or fake software update prompts. These messages distribute a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames such as “ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe” or “PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe.” When executed, the installer drops multiple DLLs, triggers a User Account Control (UAC) elevation to gain privileged context, and establishes persistence by registering Windows services and autorun Registry entries. It also modifies Windows Firewall rules to allow inbound UDP traffic to MSP360 on port 48678, ensuring uninterrupted remote access. With MSP360 in place, attackers leverage its PowerShell execution capabilities to stealthily install ScreenConnect on the compromised endpoint. This second RMM client provides a backup remote-access path and is used to transfer additional payloads, run post-compromise tools, and perform information collection and credential-access operations. Microsoft notes that ScreenConnect’s native RunFile functionality is abused to execute these payloads, further camouflaging malicious activity within legitimate administrative workflows. The combination of two trusted RMM platforms gives attackers flexibility and resilience, allowing them to maintain control even if one channel is disrupted.  In a parallel set of incidents during the same period, Microsoft observed attackers substituting MSP360 with Faronics Deploy Agent before installing ScreenConnect, indicating a broader pattern of RMM abuse. While no specific threat group has been attributed to these campaigns, the consistent use of multiple RMM tools suggests a coordinated effort to maximize persistence and minimize detection. By relying on signed, legitimate software, attackers reduce the likelihood of triggering endpoint security alerts, making these intrusions particularly challenging to identify without behavioral monitoring. Organizations are advised to enforce strict application allowlisting, monitor for unusual RMM installations, and scrutinize processes that invoke UAC elevation or modify firewall rules. Security teams should also track anomalous PowerShell activity and unexpected service registrations linked to RMM agents. As remote administration tools become increasingly weaponized, a defense-in-depth strategy combining endpoint detection, network segmentation, and user awareness training is critical to mitigating dual-RMM phishing threats.
dlvr.it
October 1, 2026 at 2:43 PM