Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Phishing Campaigns Use MSP360 for Hidden Access

Phishing Campaigns Use MSP360 for Hidden Access

Posted on September 30, 2026 By CWS

Microsoft has issued an alert regarding new phishing strategies that employ MSP360’s Remote Monitoring and Management (RMM) software. These campaigns deceive users with meeting invitations, PDF themes, and software update prompts, aiming to gain unauthorized access.

Exploiting Legitimate Software

Once the misleading MSP360 installer is executed, it sets up remote management on the target systems, allowing attackers to establish an initial foothold. This foothold is then used to deploy the ConnectWise ScreenConnect client, granting further remote access to the compromised devices.

These tactics enable the attackers to introduce additional tools and conduct data collection and credential harvesting operations. Currently, no specific threat actor or group has been identified as responsible for these activities.

Multi-Stage Intrusion Chain

The intrusion process, first detected by Microsoft in July 2026, starts with phishing emails that distribute a digitally signed MSP360 RMM installer under various deceptive names. Examples include ‘VIP_ECARD_INVITATION_rmm_v2.5.0.67’ and ‘ZoomSetup_Installation_v2.5.0.67’.

The installer files are hosted on both attacker-controlled platforms and legitimate cloud services such as Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Once executed, the installer deploys multiple DLLs and utilizes Windows User Account Control (UAC) for elevated access, ensuring persistent presence by leveraging RMM functionalities.

Remote Access and System Manipulation

Further actions involve enumerating installed .NET runtimes, registering Windows services, and creating autorun entries to ensure MSP360 launches automatically. The setup also modifies the Windows Firewall to allow traffic to MSP360 on a specific port, enhancing persistent access.

Attackers use the dual-RMM setup to hide malicious operations within typical remote administration tasks, facilitating the delivery and execution of additional payloads via ScreenConnect’s RunFile feature. Microsoft also noted similar attacks using Faronics Deploy Agent as an alternative to MSP360, demonstrating the versatility of these threat actors.

This incident underscores how malicious entities exploit legitimate software to integrate seamlessly into standard IT operations, maintaining long-term access while minimizing detection risks. The combination of MSP360 and ScreenConnect provides robust remote administration capabilities, enabling further manipulation and control over targeted systems.

The Hacker News Tags:credential access, Cybersecurity, endpoint security, IT operations, Microsoft warning, MSP360, Phishing, remote access, RMM software, ScreenConnect, social engineering, system compromise

Post navigation

Previous Post: Cloudflare Advances Quantum-Safe Internet Security
Next Post: Google Chrome Update Fixes 32 Security Vulnerabilities

Related Posts

CBI Shuts Down £390K U.K. Tech Support Scam, Arrests Key Operatives in Noida Call Center CBI Shuts Down £390K U.K. Tech Support Scam, Arrests Key Operatives in Noida Call Center The Hacker News
3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 The Hacker News
DeadLock Ransomware Enhances Resilience with Blockchain DeadLock Ransomware Enhances Resilience with Blockchain The Hacker News
How To Browse Faster and Get More Done Using Adapt Browser How To Browse Faster and Get More Done Using Adapt Browser The Hacker News
Threat Actors Exploit Vulnerability to Access Next.js Hosts Threat Actors Exploit Vulnerability to Access Next.js Hosts The Hacker News
CISA Alerts on SharePoint Flaw Amidst Active Exploitation CISA Alerts on SharePoint Flaw Amidst Active Exploitation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Chrome Update Fixes 32 Security Vulnerabilities
  • Phishing Campaigns Use MSP360 for Hidden Access
  • Cloudflare Advances Quantum-Safe Internet Security
  • Zimbra Flaw Exploited for Web Shell Deployment
  • Russian APT Star Blizzard Employs RedFlick in New Cyber Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark