Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Дата публикации: 30-09-2026 16:32:59

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected

Основное содержимое страницы с новостью.

Ravie LakshmananSep 30, 2026Endpoint Security / Social Engineering

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.

"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software," the Microsoft Security Research team said.

The initial foothold is then used to download and install a ConnectWise ScreenConnect client, offering threat actors a redundant remote-access channel to compromised endpoints. The access is then abused to deliver additional tools and carry out information collection and credential-access operations. The activity has not been attributed to any known threat actor or group.

The multi-stage intrusion chain, which the Windows maker detected in July 2026, begins with phishing emails distributing a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive names such as below -

  • VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe
  • ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe
  • PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe
  • RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe
  • SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe

The installer packages are staged on attacker-controlled infrastructure and legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.

Once launched, the installer drops multiple DLLs, while relaunching itself by invoking the Windows User Account Control (UAC) elevation workflow to run in a privileged context, establish persistent access by deploying MSP360, and leverage the RMM tool to execute PowerShell for stealthily installing ScreenConnect.

The installer also enumerates installed .NET runtimes and registers two Windows services (RMM.Agent.exe and RMM.Agent.Launcher.exe) and creates Registry-based autorun entries to ensure that MSP360 is automatically launched when users sign-in to the machine.

Furthermore, it modifies the Windows Firewall configuration to allow inbound UDP traffic to MSP360 (i.e., RMM.Agent.exe) on port 48678.

The dual-RMM remote access attack enables the attacker to transfer additional executables and facilitate post-compromise activity, while camouflaging malicious activity within regular remote administration workflows. The payloads are run through ScreenConnect's native RunFile functionality.

Microsoft said it also observed a separate set of attacks in July 2026 that switched MSP360 for Faronics Deploy Agent to find a way in, and then used it to download and install ScreenConnect. This suggests that the threat actors are putting multiple RMM tools for remote access.

"This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities," Microsoft said.

"The combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access015.7830-09-2026
2 Fake Passkey Prompts Are Targeting Microsoft 365 Users; Here's What to Check 08.2629-09-2026
3Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets09.230-09-2026
4Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor08.0129-09-2026
5Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls05.2924-09-2026
6Мошенники распространили вредоносные APK под видом приложения для водителей010.7329-09-2026
7МВД: Мошенники распространяют вирусы под видом бонусов на заправку08.3628-09-2026
8JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources09.5328-09-2026
9Angriffe auf Microsoft-SharePoint-Schwachstelle024.0628-09-2026
10Phishing-Angriffe mit echten Hotel-Buchungsdaten02525-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 14.35. Источник: thehackernews.com.