hacker-news · Crawled Oct 1, 2026
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
4 IoCs
Read original article ↗
AI Summary
Threat actors are conducting phishing campaigns using socially engineered lures to distribute a maliciously repackaged, digitally signed MSP360 RMM installer. Once executed, the installer establishes initial access and persistence, then deploys ConnectWise ScreenConnect to create a redundant remote access channel. This dual-RMM approach allows attackers to blend malicious activity with legitimate remote administration traffic, enabling post-compromise tool deployment and credential access. The same attack pattern has also been observed using Faronics Deploy Agent instead of MSP360, indicating a broader tactic of abusing legitimate remote management tools.
AI-extracted · verify before operational use
Indicators of Compromise 4 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe | Details → |
| Filename | ZoomSetup_Installation_v2.5.0.67_ oid[redacted].exe | Details → |
| Filename | RSVP_INVITATION_E_CARD_rmm_v2.5.0.67_ oid[redacted].exe | Details → |
| Filename | SSA.GOV_STATEMENT_rmm_v2.5.0.67_ oid[redacted].exe | Details → |