Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Cybersecurity experts have sounded the alarm on a new wave of phishing attacks that exploit vulnerabilities in remote monitoring and management (RMM) software, specifically MSP360 and its ScreenConnect component. These dual-RMM phishing attacks allow attackers to gain unfettered access to an organization’s internal networks, highlighting the need for enhanced security measures.

The attacks work by first compromising a managed service provider’s (MSP) RMM tool, typically through a phishing email that tricks the MSP into installing malicious software. Once inside, the attacker uses ScreenConnect, a feature within the compromised RMM platform, to gain access to connected client endpoints. This dual-RMM approach allows attackers to move laterally across networks and evade detection by security systems.

The impact is significant, with numerous organizations and MSPs reporting breaches resulting from these attacks. The attackers’ goal is not financial gain but rather to create a backdoor into the organization’s internal network for future use. This raises concerns about the long-term implications of such breaches, including potential data exfiltration and supply chain disruption.

One reason these attacks are particularly effective lies in their ability to blend in with legitimate system communications. ScreenConnect is designed to facilitate remote desktop connections between MSPs and client endpoints, making it difficult for security systems to distinguish between genuine traffic and malicious activity. This “low-and-slow” approach allows attackers to move undetected across networks until they reach sensitive areas.

The dual-RMM attack vector also leverages a fundamental aspect of RMM platforms: the trust placed in managed service providers. MSPs often have broad access to client systems, which makes them attractive targets for attackers seeking to gain entry into organizations’ internal networks. This highlights the importance of implementing robust security measures within these relationships.

As cybersecurity professionals and business leaders grapple with this emerging threat, it is essential to recognize that these attacks are not isolated incidents but rather part of a broader trend of increasing sophistication in phishing campaigns. The takeaway for readers is clear: vigilance and proactive security planning are crucial components in protecting against such threats. Regularly review your organization’s RMM tool configurations, ensure timely patching and updates, and educate employees on the dangers of suspicious emails to stay ahead of these attacks.


Source: The Hacker News — 2026-09-30