HackerFeeds

CyberSecurity News

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

The Hacker News
· September 30, 2026

AI summary

Microsoft has issued a warning about phishing campaigns that distribute MSP360 Remote Monitoring and Management software installers disguised as meeting invitations, PDF files, or software updates. The legitimate MSP360 installer is being distributed with a deceptive file name. When executed, the installer establishes remote management access on affected systems. The goal of these campaigns is to deploy ScreenConnect, although the specifics of this deployment are not detailed. The attacks are characterized as dual-RMM phishing attacks, indicating the involvement of multiple remote monitoring and management tools. These phishing campaigns rely on social engineering tactics to trick victims into executing the installer.

Read the full article at The Hacker Newsthehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.