#msp360
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns #CyberAttacks #Microsoft #MSP360RMM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Campaigns
 Microsoft has warned of a new wave of phishing campaigns that abuse the legitimate MSP360 Remote Monitoring and Management (RMM) software to establish persistent remote access on victim devices. Once this foothold is secured, attackers deploy a second RMM tool, ConnectWise ScreenConnect, creating a redundant channel for control and further malicious activity. This dual-RMM technique enables threat actors to blend into normal IT operations while carrying out credential theft and data exfiltration with reduced risk of detection.  The attack chain, observed by Microsoft in July 2026, begins with phishing emails disguised as meeting invites, PDF-related lures, or fake software update prompts. These messages distribute a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive filenames such as “ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe” or “PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe.” When executed, the installer drops multiple DLLs, triggers a User Account Control (UAC) elevation to gain privileged context, and establishes persistence by registering Windows services and autorun Registry entries. It also modifies Windows Firewall rules to allow inbound UDP traffic to MSP360 on port 48678, ensuring uninterrupted remote access. With MSP360 in place, attackers leverage its PowerShell execution capabilities to stealthily install ScreenConnect on the compromised endpoint. This second RMM client provides a backup remote-access path and is used to transfer additional payloads, run post-compromise tools, and perform information collection and credential-access operations. Microsoft notes that ScreenConnect’s native RunFile functionality is abused to execute these payloads, further camouflaging malicious activity within legitimate administrative workflows. The combination of two trusted RMM platforms gives attackers flexibility and resilience, allowing them to maintain control even if one channel is disrupted.  In a parallel set of incidents during the same period, Microsoft observed attackers substituting MSP360 with Faronics Deploy Agent before installing ScreenConnect, indicating a broader pattern of RMM abuse. While no specific threat group has been attributed to these campaigns, the consistent use of multiple RMM tools suggests a coordinated effort to maximize persistence and minimize detection. By relying on signed, legitimate software, attackers reduce the likelihood of triggering endpoint security alerts, making these intrusions particularly challenging to identify without behavioral monitoring. Organizations are advised to enforce strict application allowlisting, monitor for unusual RMM installations, and scrutinize processes that invoke UAC elevation or modify firewall rules. Security teams should also track anomalous PowerShell activity and unexpected service registrations linked to RMM agents. As remote administration tools become increasingly weaponized, a defense-in-depth strategy combining endpoint detection, network segmentation, and user awareness training is critical to mitigating dual-RMM phishing threats.
dlvr.it
October 1, 2026 at 2:43 PM
https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
MSP360 Used to Deliver ScreenConnect in Dual-RMM Phishing Chains Attackers are using MSP360 to deploy ScreenConnect in phishing operations that stack two remote monitoring and
October 1, 2026 at 12:37 PM
RMM tools in phishing chains are a red flag — MSP360, ScreenConnect showing up uninvited usually means hands-on-keyboard access. Treat unexpected remote admin tools as an incident, not a nuisance.
October 1, 2026 at 10:35 AM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks reconbee.com/attackers-ab...

#attacker #MSP360 #Phishingattack #RMM #cyberattack
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
deceptively named titles like below read more about Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
reconbee.com
October 1, 2026 at 7:21 AM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
October 1, 2026 at 12:00 AM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks: thehackernews.com/2026/09/atta...
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft says phishing attacks abuse MSP360 and ScreenConnect to maintain redundant remote access on compromised Windows endpoints.
thehackernews.com
September 30, 2026 at 10:54 PM
喂,社畜們!想用GPTs變聰明?小心,現在它變RAT了!🤖😱 還有Zimbra老屁股又被捅,Web Shell插好插滿。MSP360雙RMM釣魚更是惡毒,遠端管理變遠端控制?別再點那些『好康』連結啦! #資安警訊 #ChatGPT #RMM #Zimbra
September 30, 2026 at 10:24 PM
Microsoft warns of phishing campaigns abusing a signed MSP360 installer disguised as invites, PDFs, and update prompts. After install, attackers deploy ScreenConnect for persistent remote access and credential theft. #MSP360 #ScreenConnect #RMM
Attackers Abuse MSP360 To Deploy ScreenConnect In Dual-RMM Phishing Attacks
Microsoft warned of phishing campaigns that distribute a legitimate MSP360 Remote Monitoring and Management installer under deceptive lures such as meeting invitations, PDF-themed files, and software update prompts. After installation, the attackers use MSP360 and then ScreenConnect to maintain persistent remote access, collect credentials, and stage additional tools. #MSP360 #ScreenConnect #FaronicsDeployAgent...
www.hendryadrian.com
September 30, 2026 at 8:45 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Leer Más / Read More...
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Haz clic para acceder al contenido completo.
thehackernews.com
September 30, 2026 at 8:16 PM
ハッカーがMSP360とScreenConnectのRMMツールを悪用、永続的なアクセスと認証情報の窃取を狙う

正規のリモート監視・管理(RMM)ソフトウェアを悪用したフィッシングキャンペーンが確認されました。攻撃者はこれを使ってWindowsシステムへの永続的なアクセスを確立し、認証情報の窃取につなげています。 このキャンペーンからは、最近よく見られる攻撃傾向がうかがえます。攻撃者は脆弱性を突いたり、あからさまな独自マルウェ
ハッカーがMSP360とScreenConnectのRMMツールを悪用、永続的なアクセスと認証情報の窃取を狙う
正規のリモート監視・管理(RMM)ソフトウェアを悪用したフィッシングキャンペーンが確認されました。攻撃者はこれを使ってWindowsシステムへの永続的なアクセスを確立し、認証情報の窃取につなげています。 このキャンペーンからは、最近よく見られる攻撃傾向がうかがえます。攻撃者は脆弱性を突いたり、あからさまな独自マルウェ
blackhatnews.tokyo
September 30, 2026 at 7:12 PM
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
September 30, 2026 at 6:47 PM
Phishing delivers a digitally signed MSP360 RMM installer that establishes remote access, installs ScreenConnect, and enables credential and information theft via trusted tools.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 6:07 PM
Phishing delivers a digitally signed MSP360 RMM installer that establishes remote access, installs ScreenConnect, and enables credential and information theft via trusted tools.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 6:06 PM
Phishing delivers a digitally signed MSP360 RMM installer that establishes remote access, installs ScreenConnect, and enables credential and information theft via trusted tools.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 30, 2026 at 6:05 PM
MSP360 RMMインストーラーがフィッシング攻撃に悪用され、ScreenConnectが展開。攻撃者は遠隔操作でシステムにアクセス可能。
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft says phishing attacks abuse MSP360 and ScreenConnect to maintain redundant remote access on compromised Windows endpoints.
thehackernews.com
September 30, 2026 at 5:58 PM
September 30, 2026 at 4:41 PM
Remote tools like MSP360 and ScreenConnect are now used in phishing disguises—Zoom or PDF installs mask full control of PCs. #RemoteAccess #Cybersecurity #MSP360 #ScreenConnect #Phishing https://thedailytechfeed.com/hackers-masquerade-remote-access-tools-as-zoom-pdf-to-hijack-pcs/
September 30, 2026 at 3:25 PM
Phishing crews are getting crafty by slipping real RMM tools into fake invites and updates. Once someone clicks, they get quiet remote access that blends in with normal IT work.
Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
www.microsoft.com
September 30, 2026 at 2:14 PM
26H2 inherits USB-audio, domain sign-in & AVD black-screen bugs. Defender: MSP360 phishing installs ScreenConnect. Excel Agent GA March 2026; Copilot Voice adds desktop subtitles. Members: Event Viewer for reboots. +17 more stories
Windows 11 26H2 Known Issues: USB Audio, Domain Sign-In and AVD Black Screen Fixes
Windows 11 version 26H2 is out. The honest answer to "is it buggy?" is that it has the same known problems as the version you're probably running now. Microsoft's current issues on 24H2 and 25H2…
windowsforum.com
September 30, 2026 at 6:00 AM
@microsoft.com
Attackers abused MSP360 and ScreenConnect to establish redundant persistent access and steal credentials.
-
IOCs: adswre[.]cfd, trews[.]cfd, sdfghj[.]rd-team[.]ru
-
#Phishing #RMM #ThreatIntel
RMM Phishing Enables Persistent Access
www.microsoft.com
September 30, 2026 at 4:15 AM
Signed RMM tools as malware: phishing installs MSP360, then silently adds ScreenConnect. https://intel.threadlinqs.com/threat/TL-2026-2788 #ThreatIntel #MSP360 #ConnectWise #ScreenConnect
September 29, 2026 at 11:42 PM
Phishing lures drop legitimate MSP360 RMM, which then installs ScreenConnect as a second way in, Microsoft reports. Block unapproved RMM tools and hunt for PowerShell spawned by RMM.Agent.exe. https://cti.securitycyber.uk
September 29, 2026 at 11:39 PM