Attackers Abuse MSP360 RMM to Deploy ScreenConnect in Dual-RMM Phishing Campaigns
Microsoft warns of phishing lures distributing legitimate MSP360 installers to establish remote access and deploy ScreenConnect as a secondary RMM for persistence.

Key Takeaways
- Phishing campaigns distribute legitimate MSP360 RMM installers under deceptive lures.
- Execution grants attackers remote management access on affected endpoints.
- ScreenConnect is deployed as a secondary RMM for dual-RMM persistence.
- No zero-day vulnerabilities are exploited; the attack relies on user interaction.
Related Security News

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver Remote Access Trojans (RATs). Huntress observed the activity in late September 2026, marking another instance of abuse in trusted artificial intelligence platforms. The campaign directs victims from AI-generated content to external sites using ClickFix social engineering lures that trick users into executing commands that deliver malware.




