Phishing Abuses RMM Tools for Persistent Access

Executive Summary

Microsoft Security observed phishing campaigns that leveraged the MSP360 Remote Management (RMM) tool to deploy the remote‑access software ScreenConnect. The attackers used the RMM channel to establish redundant remote‑access pathways, enabling persistent footholds for subsequent malicious activity.


Intelligence Metadata - Source Publisher: Microsoft Security - Published Date: 2026-09-29T21:39:27+00:00 - Category: threat-intel

Original Description: Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.

"Nature takes away any faculty that is not used."

— William R. Inge
Source: Microsoft Security