MEDIUMPhishing
Global

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

·Source: The Hacker News

Updated:

Executive Summary

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected

Analysis

Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
Source Attribution

Originally published by The Hacker News on Sep 30, 2026.

Related Threats

CRITICALPhishing

ABB Protection and Control IED Manager PCM600

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-274-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.</strong></p> <p>The following versions of ABB Protection and Control IED Manager PCM600 are affected:</p> <ul> <li>Pro

CVE-2026-15952CVE-2026-15953
CISA Advisories
MEDIUMPhishing

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

The Hacker News
CRITICALPhishing

The MFA you have isn’t the MFA you think you have

For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they’ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason — adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopt

CSO Online