Find notable cyber news and cases, enriched with sources, timelines, and signals.

MSP360 RMM phishing campaign deploying ScreenConnect

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A phishing campaign is using deceptive MSP360 RMM installers to establish remote management access on endpoints and then stage ConnectWise ScreenConnect, expanding the attackers' ability to persist and operate remotely. The lure set includes meeting invitations, PDF-themed files, and software-update prompts, while the installer can relaunch through UAC to run with elevated privileges. Microsoft also observed a separate July 2026 wave that swapped in Faronics Deploy Agent, showing the same operation can pivot across multiple remote-management tools.

Related Happenings

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign
H score30 First: 30.09.2026 13:45 Last: 30.09.2026 13:45 Sources 1

About this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...

Faronics Deploy phishing campaign to install ScreenConnect

Campaign
H score34 First: 01.09.2026 23:53 Last: 01.09.2026 23:53 Sources 1

About this happening: A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and...

SynkLoader Microsoft Teams help-desk phishing campaign

Campaign
H score35 First: 21.08.2026 21:01 Last: 21.08.2026 21:01 Sources 1

About this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...

ConnectWise ScreenConnect remote access installation chain

Malware Activity
H score29 First: 05.08.2026 20:49 Last: 05.08.2026 20:49 Sources 1

About this happening: A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...

COLDCARD ScreenConnect phishing campaign

Campaign
H score39 First: 05.08.2026 20:49 Last: 05.08.2026 20:49 Sources 1

About this happening: A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...

Timeline

  1. 30.09.2026 19:32 2 articles · 2h ago

    MSP360 RMM phishing campaign deploying ScreenConnect

    Initial Disclosure

    Phishing emails start the chain by delivering a disguised MSP360 RMM v2.5.0.67 installer under meeting-invitation, PDF, and software-update themes. The first execution establishes remote management access and prepares the endpoint for later ScreenConnect deployment.

    Show sources