Microsoft warned of phishing campaigns that distribute a legitimate MSP360 Remote Monitoring and Management installer under deceptive lures such as meeting invitations, PDF-themed files, and software update prompts. After installation, the attackers use MSP360 and then ScreenConnect to maintain persistent remote access, collect credentials, and stage additional tools. #MSP360 #ScreenConnect #FaronicsDeployAgent
Keypoints
- Phishing emails deliver a signed MSP360 RMM installer disguised as common documents and invitations.
- The installer creates initial remote access and deploys ScreenConnect for a second access channel.
- Attackers use UAC elevation, DLL drops, and Windows services to establish persistence.
- The campaign modifies firewall settings and autorun entries to keep MSP360 active.
- Microsoft also observed a related intrusion using Faronics Deploy Agent before installing ScreenConnect.
Read More: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html