thehackernews.com 30 Sept 2026, 16:32 UTC

Microsoft Warns of Dual RMM Attack Using MSP360 and ScreenConnect

MICROSOFT has flagged a multi-stage phishing campaign that abuses the MSP360 Remote Monitoring and Management (RMM) tool to gain initial footholds on Windows devices, then deploy a ScreenConnect client for a second, redundant remote-access channel. The attacker-delivered MSP360 installer is distributed under deceptive file names and social-engineering prompts (invites, PDFs, software updates, etc.).

Once launched, the installer drops multiple DLLs, relaunches via the Windows UAC flow to run with elevated privileges, and establishes persistent access by deploying MSP360 itself before using the RMM tool to run PowerShell for stealthy installation of ScreenConnect.

Microsoft observed that the attacker’s initial foothold also enumerates installed .NET runtimes, creates two Windows services (RMM.Agent[.]exe and RMM.Agent.Launcher[.]exe), and adds Registry-based autorun entries to ensure MSP360 launches at sign-in. The malware then modifies the Windows Firewall to allow inbound UDP traffic on port 48678 for MSP360, enabling persistent access and facilitating post-compromise activity.

ScreenConnect is used to extend and camouflage the attacker’s control, with payloads executed through ScreenConnect’s RunFile function. The campaign is described as dual-RMM abuse, providing redundant channels for instrumenting commands, transferring additional tools, and conducting information collection and credential-access operations.

While Microsoft notes a separate July 2026 wave that used Faronics Deploy Agent, the MSP360/ScreenConnect chain shows threat actors seeking multiple remote‑access options to blend into normal IT workflows. No actor attribution has been made yet.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline