Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Phishing campaigns abuse signed MSP360 installers to deploy ScreenConnect and establish dual remote-access footholds.
Microsoft warned that July 2026 phishing campaigns delivered a digitally signed MSP360 Remote Monitoring and Management installer, version 2.5.0.67, under meeting, PDF, software-update, and government-statement lures. The installer elevates through UAC, registers RMM agent services, opens UDP port 48678, and then installs ConnectWise ScreenConnect as a second remote-access channel. Installers were staged on attacker infrastructure and legitimate clouds including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. A related cluster used Faronics Deploy Agent instead of MSP360 before installing ScreenConnect, and the activity remains unattributed.