← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Phishing campaigns distribute MSP360 RMM installer.
  • MSP360 provides initial remote management access.
  • ScreenConnect client is installed for redundant access.
  • Attackers use dual-RMM for post-compromise activities.

Phishing Campaigns Distribute Legitimate RMM Software

Microsoft has issued a warning regarding ongoing phishing campaigns that distribute an installer for the legitimate MSP360 Remote Monitoring and Management (RMM) software. These campaigns use social engineering tactics, such as fake meeting invitations, PDF lures, and software update prompts, to trick users into executing the installer.

The MSP360 installer, version 2.5.0.67, is digitally signed and distributed under deceptive file names like "VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe" and "ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe". These installers are hosted on legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.

Establishing Dual Remote Access

Upon execution, the MSP360 installer establishes remote management access on the affected device, providing attackers with an initial foothold using trusted administrative software. This initial access is then leveraged to download and install a ConnectWise ScreenConnect client.

The installation of a second RMM tool, ScreenConnect, creates a redundant remote-access channel to compromised endpoints. This dual-RMM approach ensures persistent access for threat actors, even if one channel is detected or disrupted.

Post-Compromise Activities

The established remote access is subsequently abused to deliver additional tools, collect information, and perform credential-access operations. The use of legitimate RMM tools helps camouflage malicious activity within regular remote administration traffic, making detection more difficult.

The multi-stage intrusion chain, detected by Microsoft in July 2026, involves the installer dropping multiple DLLs, invoking Windows User Account Control (UAC) for privileged execution, and establishing persistence through Windows services and Registry autorun entries. It also modifies Windows Firewall to allow inbound UDP traffic for MSP360 on port 48678.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Microsoft has warned of phishing campaigns distributing MSP360 Remote Monitoring and Management (RMM) software to gain initial access to systems. Attackers then use this foothold to install ConnectWise ScreenConnect, establishing redundant remote access channels for further malicious activity.