MSP360 RMM phishing campaign deploying ScreenConnect
Campaign
Summary
Hide ▲
Show ▼
A phishing campaign is using deceptive MSP360 RMM installers to establish remote management access on endpoints and then stage ConnectWise ScreenConnect, expanding the attackers' ability to persist and operate remotely. The lure set includes meeting invitations, PDF-themed files, and software-update prompts, while the installer can relaunch through UAC to run with elevated privileges. Microsoft also observed a separate July 2026 wave that swapped in Faronics Deploy Agent, showing the same operation can pivot across multiple remote-management tools.
Related Happenings
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
Campaign
H score30
First: 30.09.2026 13:45
Last: 30.09.2026 13:45
Sources 1
About this happening:
The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
CampaignAbout this happening: The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and b...
Faronics Deploy phishing campaign to install ScreenConnect
Campaign
H score34
First: 01.09.2026 23:53
Last: 01.09.2026 23:53
Sources 1
About this happening:
A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and...
Faronics Deploy phishing campaign to install ScreenConnect
CampaignAbout this happening: A phishing campaign is abusing Faronics Deploy to enroll victim endpoints and install ConnectWise ScreenConnect, giving attackers remote administrative control and...
SynkLoader Microsoft Teams help-desk phishing campaign
Campaign
H score35
First: 21.08.2026 21:01
Last: 21.08.2026 21:01
Sources 1
About this happening:
The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
SynkLoader Microsoft Teams help-desk phishing campaign
CampaignAbout this happening: The SynkLoader campaign is using Microsoft Teams help-desk impersonation and a fake PowerShell Cleaner MSI to push victims into a credential-theft chain that can open...
ConnectWise ScreenConnect remote access installation chain
Malware Activity
H score29
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
About this happening:
A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
ConnectWise ScreenConnect remote access installation chain
Malware ActivityAbout this happening: A malicious installer chain is now deploying ConnectWise ScreenConnect through a batch file and setup.msi, giving operators remote access to victim devices. The pa...
COLDCARD ScreenConnect phishing campaign
Campaign
H score39
First: 05.08.2026 20:49
Last: 05.08.2026 20:49
Sources 1
About this happening:
A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
COLDCARD ScreenConnect phishing campaign
CampaignAbout this happening: A COLDCARD-themed phishing campaign is using a fake security-audit lure to push victims into installing ScreenConnect remote access software, creating a route to device ta...
Timeline
-
30.09.2026 19:32 2 articles · 2h ago
MSP360 RMM phishing campaign deploying ScreenConnect
Initial DisclosurePhishing emails start the chain by delivering a disguised MSP360 RMM v2.5.0.67 installer under meeting-invitation, PDF, and software-update themes. The first execution establishes remote management access and prepares the endpoint for later ScreenConnect deployment.
Show sources
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks — thehackernews.com — 30.09.2026 19:32
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks — thehackernews.com — 30.09.2026 19:32