hacker-news · Crawled Oct 1, 2026

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

4 IoCs
Read original article ↗

AI Summary

Threat actors are conducting phishing campaigns using socially engineered lures to distribute a maliciously repackaged, digitally signed MSP360 RMM installer. Once executed, the installer establishes initial access and persistence, then deploys ConnectWise ScreenConnect to create a redundant remote access channel. This dual-RMM approach allows attackers to blend malicious activity with legitimate remote administration traffic, enabling post-compromise tool deployment and credential access. The same attack pattern has also been observed using Faronics Deploy Agent instead of MSP360, indicating a broader tactic of abusing legitimate remote management tools.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Filename VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe Details →
Filename ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe Details →
Filename RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe Details →
Filename SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe Details →