Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Executive Summary
Microsoft warned that attackers are distributing a legitimate MSP360 RMM installer under deceptive file names via phishing emails, meeting invites, PDFs, and software update prompts. Once executed, the installer grants remote management access and is used to deploy ScreenConnect, enabling attackers to control victim systems.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-09-30T16:32:59+00:00 - Category: threat-intel
Original Description: Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
"They must often change, who would be constant in happiness or wisdom."
— Confucius