negativeSYS.SOURCE: The Hacker News• 2026-09-30T22:02:59+05:30
Phishing Campaigns Leverage MSP360 and ScreenConnect in Dual-RMM Attacks
Attackers use deceptive phishing emails to distribute a modified MSP360 RMM installer, establishing persistent access and deploying ScreenConnect for dual-RMM remote access. The campaign employs cloud infrastructure and system-level privileges to evade detection and facilitate data exfiltration.
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
"Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
*** END OF TRANSMISSION ***