Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual‑RMM Phishing Campaigns

Threat actors are distributing a legitimate MSP360 RMM installer via phishing emails, then using it to install ScreenConnect remote‑access software. The campaign highlights gaps in vendor‑risk monitoring and remote‑access controls, underscoring the need for continuous audit evidence.

LiveThreat™ Intelligence · 📅 September 30, 2026· 📰 thehackernews.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual‑RMM Phishing Campaigns

What Happened — Microsoft warned that threat actors are running phishing campaigns that distribute a legitimate MSP360 Remote Monitoring and Management (RMM) installer disguised as meeting invitations, PDF‑styled lures, or fake update prompts. Once the installer runs, it grants the attacker remote‑management access, which is then used to silently install the ScreenConnect remote‑access tool, creating a “dual‑RMM” foothold on victim endpoints.

Why It Matters for Trust & Control Assurance —

  • Shows how a trusted third‑party tool can become an attack vector, reinforcing the need for continuous vendor‑risk monitoring and evidence of secure configuration.
  • Highlights the importance of logging and alerting on RMM usage, providing a defensible audit trail for any remote‑access activity.
  • Demonstrates that phishing‑based delivery of legitimate software bypasses traditional malware detection, making identity‑and‑access controls and security‑awareness training critical.

Who Is Affected — Managed Service Providers (MSPs), IT service firms, and any organization that relies on third‑party RMM solutions for endpoint management, across sectors such as technology, finance, healthcare, and government.

Recommended Actions —

  • Review and tighten procurement and usage policies for RMM tools; enforce least‑privilege configurations.
  • Implement continuous monitoring of RMM activity and integrate logs into a centralized SIEM for real‑time detection.
  • Conduct phishing awareness training and simulate attacks that include legitimate‑software lures.
  • Verify the integrity of RMM installers via hash checks and secure distribution channels before deployment. Source: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html

Technical Notes — Attack vector: phishing emails with malicious attachments that deliver a legitimate MSP360 installer; subsequent payload: ScreenConnect remote‑access tool. No public CVE; the compromise stems from social engineering and misuse of trusted software. Source: https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html

📰 Original Source
https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →