{"id":3279,"date":"2026-09-30T18:58:53","date_gmt":"2026-09-30T18:58:53","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3279"},"modified":"2026-09-30T18:58:53","modified_gmt":"2026-09-30T18:58:53","slug":"attackers-abuse-msp360-to-deploy-screenconnect-in-dual-rmm-phishing-attacks","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3279","title":{"rendered":"Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 30, 2026<\/span><\/span><span class=\"p-tags\">Endpoint Security \/ Social Engineering<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiOOpLuI3TSRRvKO7zux2AsJKVNjC36RcaAJCYelekCSQRhpMSABekI8kmMGLZRBZN2biNqDGyKYY_0AqsXb2PMKS6M3sjeLBlt7UQ_IWhXPQ3_q9DGhetIgFeGkF1d_ZE-l2HZPTDID5FkqdLsv3G_wJ-Yckb-Q2I6FdCLo3-AS-pPbCIDRfgFiRzofpaA\/s1700-nu-rw-lo-l85-e365\/windows-rmm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.<\/p>\n<p>\u00abOnce executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected devices and enabled threat actors to gain an initial foothold using trusted administrative software,\u00bb the Microsoft Security Research team <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/09\/29\/phishing-abuses-rmm-tools-persistent-access\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>The initial foothold is then used to download and install a ConnectWise ScreenConnect client, offering threat actors a redundant remote-access channel to compromised endpoints. The access is then abused to deliver additional tools and carry out information collection and credential-access operations. The activity has not been attributed to any known threat actor or group.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The multi-stage intrusion chain, which the Windows maker detected in July 2026, begins with phishing emails distributing a digitally signed MSP360 RMM v2.5.0.67 installer under deceptive names such as below &#8211;<\/p>\n<p><a name=\"more\"\/><\/p>\n<ul>\n<li>VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe<\/li>\n<li>ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe<\/li>\n<li>PDF Reader &amp; Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe<\/li>\n<li>RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe<\/li>\n<li>SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe<\/li>\n<\/ul>\n<p>The installer packages are staged on attacker-controlled infrastructure and legitimate cloud services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase.<\/p>\n<p>Once launched, the installer drops multiple DLLs, while relaunching itself by invoking the Windows User Account Control (UAC) elevation workflow to run in a privileged context, establish persistent access by deploying MSP360, and leverage the RMM tool to execute PowerShell for stealthily installing ScreenConnect.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1UiAbAKobATGslP6tggbsq5uf_d4pGl09cIJuxA7QxQmNmelHJWxOqQ9U4rm5rralrWkCCgkucLtWZwJbEduKo6A-bkBVCSIinkzzzMIhfx8VvWU_O7QMry9851lbsC3lKJBDsdCYFROodhuMj0i1gGdEW72Q_H2qH2LFWBROnco3BBSSkMGn0X9EWLzZ\/s1700-nu-rw-lo-l85-e365\/rrm.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi1UiAbAKobATGslP6tggbsq5uf_d4pGl09cIJuxA7QxQmNmelHJWxOqQ9U4rm5rralrWkCCgkucLtWZwJbEduKo6A-bkBVCSIinkzzzMIhfx8VvWU_O7QMry9851lbsC3lKJBDsdCYFROodhuMj0i1gGdEW72Q_H2qH2LFWBROnco3BBSSkMGn0X9EWLzZ\/s1700-nu-rw-lo-l85-e365\/rrm.jpg\" alt=\"\" border=\"0\" data-original-height=\"548\" data-original-width=\"975\"\/><\/a><\/div>\n<p>The installer also enumerates installed .NET runtimes and registers two Windows services (<a href=\"https:\/\/lolrmm.io\/tools\/msp360\" target=\"_blank\">RMM.Agent.exe<\/a> and RMM.Agent.Launcher.exe) and creates Registry-based autorun entries to ensure that MSP360 is automatically launched when users sign-in to the machine.<\/p>\n<p>Furthermore, it modifies the Windows Firewall configuration to allow inbound UDP traffic to MSP360 (i.e., RMM.Agent.exe) on port 48678.<\/p>\n<p>The dual-RMM remote access attack enables the attacker to transfer additional executables and facilitate post-compromise activity, while camouflaging malicious activity within regular remote administration workflows. The payloads are run through ScreenConnect&#8217;s native RunFile functionality.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Microsoft said it also observed a separate set of attacks in July 2026 that switched MSP360 for Faronics Deploy Agent to find a way in, and then used it to download and install ScreenConnect. This suggests that the threat actors are putting multiple RMM tools for remote access.<\/p>\n<p>\u00abThis activity highlights how threat actors continue to abuse legitimate remote administration software to blend into normal IT operations while maintaining persistent access and reducing detection opportunities,\u00bb Microsoft said.<\/p>\n<p>\u00abThe combination of MSP360 and ScreenConnect provided the threat actor with redundant remote administration channels and enabled the transfer, execution, and management of additional tooling during subsequent stages of the intrusion.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 30, 2026Endpoint Security \/ Social Engineering Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3280,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[383,622,24,229,3608,3607,390,863],"class_list":["post-3279","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-abuse","tag-attackers","tag-attacks","tag-deploy","tag-dualrmm","tag-msp360","tag-phishing","tag-screenconnect"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3279"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3279\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3280"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}