Microsoft has warned of phishing campaigns delivering an installer for the MSP360 Remote Monitoring and Management (RMM) software through fake meeting invites, PDF-themed lures, software update prompts, and other social-engineering content.
The legitimate MSP360 installer, which had been distributed under a deceptive file name, allowed attackers to establish remote management access on the targeted devices and provide an initial foothold by using trusted administrative software, Microsoft Security Research team said.
The initial foothold was later used to download and install a ConnectWise ScreenConnect client, providing a redundant remote-access channel for the compromised endpoints. The access was then abused to deliver additional tools and perform information collection and credential-access operations. The activity has not been attributed to any known threat actor or group.
The multi-stage intrusion chain, which Microsoft Windows vendor unearthed in July 2026, commences with phishing e-mails, which deliver a digitally signed MSP360 RMM v2.5.0.67 installer under deceptively named titles like below read more about Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
