Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft warned of phishing campaigns that distribute a legitimate MSP360 Remote Monitoring and Management installer under deceptive lures such as meeting invitations, PDF-themed files, and software update prompts. After installation, the attackers use MSP360 and then ScreenConnect to maintain persistent remote access, collect credentials, and stage additional tools. #MSP360 #ScreenConnect #FaronicsDeployAgent

Keypoints

  • Phishing emails deliver a signed MSP360 RMM installer disguised as common documents and invitations.
  • The installer creates initial remote access and deploys ScreenConnect for a second access channel.
  • Attackers use UAC elevation, DLL drops, and Windows services to establish persistence.
  • The campaign modifies firewall settings and autorun entries to keep MSP360 active.
  • Microsoft also observed a related intrusion using Faronics Deploy Agent before installing ScreenConnect.

Read More: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html