Attackers are weaponizing legitimate remote management tools in a multi-stage infection chain that chains MSP360 and ScreenConnect to establish persistent network access, Microsoft security researchers have determined.

The phishing campaigns distribute a genuine MSP360 Remote Monitoring and Management installer but rename it with innocent-sounding filenames to bypass user suspicion. The social engineering tactics vary. Attackers send messages mimicking meeting invitations, PDF documents, software update notifications, and other workplace-themed content. Once a user executes the MSP360 installer, attackers gain initial foothold access to the target system.

The attack sequence moves into a second phase once MSP360 runs successfully. Threat actors leverage the already-installed RMM software to drop and execute ScreenConnect, a separate legitimate remote access tool. This dual-RMM approach gives attackers redundant command and control channels. If defenders identify and remove one RMM application, the second tool maintains persistence and allows continued lateral movement within the network.

The use of legitimate software as an attack vector complicates endpoint detection. Security tools that flag malware signatures generate fewer alerts when legitimate MSP360 and ScreenConnect binaries execute. Organizations relying on application whitelisting face challenges distinguishing malicious use of legitimate tools from authorized system administration activity.

Microsoft's warning emphasizes organizational phishing response. Email filtering rules should scrutinize messages containing file attachments claiming to be meeting invitations or software updates when sent from external sources. User education around unexpected file execution remains a defensive cornerstone. Many organizations still lack mandatory user verification workflows before granting executable permissions on corporate devices.

The MSP360 and ScreenConnect combination targets managed service provider environments and enterprise IT infrastructure. MSPs typically deploy monitoring tools across hundreds of customer environments, making a single compromised MSP account a lateral escalation point affecting numerous downstream organizations. ScreenConnect deployment follows the initial foothold, enabling remote command execution and file transfer capabilities.

Defenders should monitor process execution chains where MSP360 spawns secondary executable processes. Network segmentation that restricts which systems can communicate with RMM infrastructure limits attacker movement after initial compromise. Credential inspection of accounts used by both MSP360 and ScreenConnect services prevents reuse across networks.

The campaign represents a broader industry shift toward living-off-the-land attacks. Rather than deploying custom malware that triggers signature-based detection, threat actors abuse pre-existing administrative tools already present in target environments or widely trusted by users. This approach reduces malware samples submitted to analysis engines and extends the time attackers remain undetected.

Organizations should require multi-factor authentication on all RMM accounts, restrict RMM installations to specific user groups, and maintain detailed audit logs of RMM software initialization events. Network-level monitoring of ScreenConnect communication patterns to external servers provides another detection layer.

The attacks underscore why RMM software selection requires careful vetting. Solutions from reputable vendors carry lower compromise risk than alternatives, though no vendor is immune to abuse by threat actors once legitimate credentials fall into adversary hands.