Thehackernews Phishing Campaign Exploits MSP360 and ScreenConnect for Remote Access
Article Content
- •Attackers exploit MSP360 to deploy ScreenConnect via phishing emails.
- •The campaign utilizes social engineering tactics with familiar workplace themes.
- •Organizations should implement strict controls and multi-factor authentication for RMM tools.
A phishing campaign has been identified that abuses the MSP360 remote management software to gain persistent access to Windows systems. Attackers distribute a legitimate MSP360 installer disguised as trusted software, which, once executed, downloads and installs ConnectWise ScreenConnect, providing an additional remote access channel. The campaign employs social engineering tactics, using familiar workplace themes such as meeting invitations and software updates to lure victims. Microsoft security researchers detected this activity in July 2026, and the attackers utilized legitimate cloud services to host malicious payloads. MSP360 has since blocked accounts associated with this abuse and implemented stronger safeguards. The dual-RMM approach allows attackers to maintain access even if one tool is removed. Organizations are advised to enforce multi-factor authentication and application control policies to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Common questions
What software is being exploited?
How can we protect our organization?
What should we do if we suspect a compromise?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…