A wave of dual-RMM phishing attacks is sweeping across the globe, with attackers exploiting a vulnerability in MSP360’s integration with ScreenConnect to gain unauthorized access to businesses’ internal networks. The compromised systems are then used as a springboard for further reconnaissance and lateral movement, putting sensitive data at risk.
The scheme involves attackers leveraging a weakness in MSP360’s API connection to ScreenConnect, which enables remote monitoring and management (RMM) capabilities. Once inside the network, they use this access to deploy a ScreenConnect agent on compromised endpoints, effectively turning these systems into unwitting accomplices in the attack. The dual-RMM approach allows attackers to bypass traditional security controls, leaving defenders scrambling to contain the breach.
The attacks are especially concerning due to their stealthy nature and the level of sophistication involved. As MSP360’s integration with ScreenConnect is a legitimate business arrangement, it can be challenging for organizations to distinguish between genuine activity and malicious behavior. Furthermore, the exploitation of this vulnerability requires little more than basic technical expertise, making it an attractive option for less-skilled threat actors.
While the specific tactics employed by these attackers are unique, the underlying motive is familiar: financial gain through data theft or disruption of business operations. The fact that MSP360’s integration with ScreenConnect has been compromised raises questions about the security posture of managed service providers (MSPs) and their clients alike. With an increasing reliance on cloud-based services and APIs, it’s essential for organizations to reevaluate their risk management strategies and prioritize robust threat detection and incident response capabilities.
The recent wave of dual-RMM phishing attacks highlights the ongoing cat-and-mouse game between attackers and defenders in the cybersecurity landscape. As new vulnerabilities emerge, it’s crucial that businesses prioritize proactive security measures, such as regular software updates, network segmentation, and employee education. Furthermore, MSPs must take concrete steps to address the security implications of their integration with ScreenConnect, including implementing additional authentication protocols and conducting thorough vulnerability assessments.
In light of these attacks, organizations would do well to review their security controls and consider implementing additional layers of protection, such as network monitoring tools or endpoint detection and response (EDR) solutions. By staying vigilant and adapting to the evolving threat landscape, businesses can minimize the risk of falling victim to these types of attacks and protect themselves from the devastating consequences of a successful breach.
Source: The Hacker News — 2026-09-30