Ethical Hacking News
Microsoft has issued a warning about a sophisticated phishing campaign that exploits the MSP360 Remote Monitoring and Management (RMM) software to gain unauthorized access to endpoints. Attackers have been using the software to deploy the ScreenConnect client, creating a dual-RMM remote access attack that enables threat actors to transfer additional tooling and carry out information collection and credential-access operations.
Microsoft has warned of a phishing campaign using MSP360 RMM software to gain unauthorized access to endpoints. The attackers deploy the ScreenConnect client, creating a dual-RMM remote access attack. The phishing campaign, starting in July 2026, distributes digitally signed installer files under deceptive names. The attackers establish persistent access by deploying MSP360, leveraging RMM tool, and executing PowerShell. The dual-RMM remote access attack enables transfer of additional tooling and carry out information collection. Threat actors are using multiple RMM tools for remote access, including Faronics Deploy Agent. The use of MSP360 and ScreenConnect in phishing campaigns is a growing concern.
Microsoft has sounded the alarm on a sophisticated phishing campaign that exploits the MSP360 Remote Monitoring and Management (RMM) software to gain unauthorized access to endpoints. According to a recent warning from Microsoft's Security Research team, attackers have been using the MSP360 RMM software to deploy the ScreenConnect client, creating a dual-RMM remote access attack that enables threat actors to transfer additional tooling and carry out information collection and credential-access operations.
The phishing campaign, which began in July 2026, involves the distribution of digitally signed MSP360 RMM v2.5.0.67 installer files under deceptive names such as VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, ZoomSetup_Installation_v2.5.0.67_oid[redacted].exe, and PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exe. Once launched, the installer drops multiple DLLs and relaunches itself, establishing persistent access by deploying MSP360 and leveraging the RMM tool to execute PowerShell for stealthily installing ScreenConnect.
The attackers also enumerate installed .NET runtimes, register two Windows services (RMM.Agent.exe and RMM.Agent.Launcher.exe), and create Registry-based autorun entries to ensure that MSP360 is automatically launched when users sign-in to the machine. Furthermore, the installer modifies the Windows Firewall configuration to allow inbound UDP traffic to MSP360 (i.e., RMM.Agent.exe) on port 48678.
The dual-RMM remote access attack enables the attacker to transfer additional executables and facilitate post-compromise activity, while camouflaging malicious activity within regular remote administration workflows. Microsoft observed a separate set of attacks in July 2026 that used Faronics Deploy Agent instead of MSP360 to find a way in, and then used it to download and install ScreenConnect, suggesting that the threat actors are putting multiple RMM tools for remote access.
"This activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities," Microsoft said. "The combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion."
The use of MSP360 and ScreenConnect in phishing campaigns is a growing concern, as it allows threat actors to exploit legitimate remote administration software to gain unauthorized access to endpoints. This highlights the importance of staying vigilant and keeping software up-to-date to prevent falling victim to these types of attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/Microsoft-Warns-of-Sophisticated-Phishing-Campaigns-Exploiting-MSP360-Remote-Monitoring-and-Management-Software-ehn.shtml
https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
Published: Wed Sep 30 13:14:24 2026 by llama3.2 3B Q4_K_M