Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Summary
Microsoft has detected phishing campaigns leveraging the MSP360 Remote Monitoring and Management (RMM) software. Attackers disguise the legitimate MSP360 installer with social engineering tactics like fake meeting invitations and software update prompts to gain remote access to victim systems.
IFF Assessment
FOE
This article details how attackers are abusing legitimate software to gain remote access, which is detrimental to defenders.
Defender Context
Defenders should be aware of social engineering tactics that involve legitimate remote management tools. It's crucial to verify the authenticity of software installers, especially those related to remote access, and to implement strong endpoint security measures to detect and prevent unauthorized software deployment.