Attackers Abuse MSP360 to Deploy ScreenConnect in Dual‑RMM Phishing Campaigns
What Happened — Microsoft warned that threat actors are running phishing campaigns that distribute a legitimate MSP360 Remote Monitoring and Management (RMM) installer disguised as meeting invitations, PDF‑styled lures, or fake update prompts. Once the installer runs, it grants the attacker remote‑management access, which is then used to silently install the ScreenConnect remote‑access tool, creating a “dual‑RMM” foothold on victim endpoints.
Why It Matters for Trust & Control Assurance —
- Shows how a trusted third‑party tool can become an attack vector, reinforcing the need for continuous vendor‑risk monitoring and evidence of secure configuration.
- Highlights the importance of logging and alerting on RMM usage, providing a defensible audit trail for any remote‑access activity.
- Demonstrates that phishing‑based delivery of legitimate software bypasses traditional malware detection, making identity‑and‑access controls and security‑awareness training critical.
Who Is Affected — Managed Service Providers (MSPs), IT service firms, and any organization that relies on third‑party RMM solutions for endpoint management, across sectors such as technology, finance, healthcare, and government.
Recommended Actions —
- Review and tighten procurement and usage policies for RMM tools; enforce least‑privilege configurations.
- Implement continuous monitoring of RMM activity and integrate logs into a centralized SIEM for real‑time detection.
- Conduct phishing awareness training and simulate attacks that include legitimate‑software lures.
- Verify the integrity of RMM installers via hash checks and secure distribution channels before deployment. Source: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
Technical Notes — Attack vector: phishing emails with malicious attachments that deliver a legitimate MSP360 installer; subsequent payload: ScreenConnect remote‑access tool. No public CVE; the compromise stems from social engineering and misuse of trusted software. Source: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html