Skip to content
Phishing Campaign Exploits MSP360 and ScreenConnect for Remote Access

Phishing Campaign Exploits MSP360 and ScreenConnect for Remote Access

First seen 1 Oct 2026, 15:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 16:03 UTC
  • •Attackers exploit MSP360 to deploy ScreenConnect via phishing emails.
  • •The campaign utilizes social engineering tactics with familiar workplace themes.
  • •Organizations should implement strict controls and multi-factor authentication for RMM tools.

A phishing campaign has been identified that abuses the MSP360 remote management software to gain persistent access to Windows systems. Attackers distribute a legitimate MSP360 installer disguised as trusted software, which, once executed, downloads and installs ConnectWise ScreenConnect, providing an additional remote access channel. The campaign employs social engineering tactics, using familiar workplace themes such as meeting invitations and software updates to lure victims. Microsoft security researchers detected this activity in July 2026, and the attackers utilized legitimate cloud services to host malicious payloads. MSP360 has since blocked accounts associated with this abuse and implemented stronger safeguards. The dual-RMM approach allows attackers to maintain access even if one tool is removed. Organizations are advised to enforce multi-factor authentication and application control policies to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-07-01
Phishing campaign detected
Microsoft security researchers identified a phishing campaign using MSP360 to gain remote access.
Brusselsmorning
2026-10-01
MSP360 strengthens security measures
MSP360 blocked accounts involved in the abuse and enhanced safeguards against misuse.
Brusselsmorning

More articles in this cluster (3)

Common questions

What software is being exploited?
The MSP360 remote management software is being exploited to gain unauthorized access.
How can we protect our organization?
Implement multi-factor authentication and application control policies for remote management tools.
What should we do if we suspect a compromise?
Immediately reset credentials for affected services and conduct a thorough investigation of the systems.