Interestana
Home/News/Attackers Abuse MSP360 for ScreenConnect Deployment
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Abuse MSP360 for ScreenConnect Deployment

Attackers Abuse MSP360 for ScreenConnect Deployment

Microsoft has issued a warning regarding sophisticated phishing campaigns that are exploiting the legitimate MSP360 Remote Monitoring and Management (RMM) software. Attackers are distributing an installer for MSP360 under deceptive pretenses, masquerading it as meeting invitations, PDF-themed lures, or software update prompts. This social engineering tactic aims to trick unsuspecting users into executing the malicious payload. Once the legitimate MSP360 installer is executed under a deceptive file name, it establishes remote management access on the affected systems. This initial access is then leveraged by threat actors to deploy the ScreenConnect remote access tool, which is also a legitimate software but is being abused for malicious purposes. The dual abuse of legitimate tools like MSP360 and ScreenConnect highlights a growing trend in cyberattacks where attackers leverage trusted software to bypass security measures and gain a foothold within target networks. The MSP360 installer, when executed, facilitates the establishment of remote management capabilities. This capability is then utilized by the attackers to deploy ScreenConnect, a tool commonly used for legitimate remote support and IT administration. However, in these phishing attacks, ScreenConnect is deployed to enable unauthorized remote access for malicious activities. The use of MSP360's installer is particularly concerning because it is a legitimate software, which can make it harder for security systems to detect and block. The social engineering tactics employed, such as impersonating meeting invitations or software updates, are designed to exploit human trust and urgency. This allows the attackers to gain initial access and then proceed with the deployment of ScreenConnect. The ultimate goal of these attacks is to gain persistent remote access to victim systems, which can then be used for a variety of nefarious purposes, including data theft, ransomware deployment, or further network compromise. Microsoft's advisory serves as a critical alert to organizations and individuals to be vigilant against such sophisticated phishing attempts and to ensure that software is downloaded only from official and trusted sources. The abuse of MSP360's installer represents a significant threat, as it leverages a tool designed for legitimate remote management to facilitate unauthorized access and subsequent malicious actions. The attackers' strategy involves a two-stage process: first, gaining initial access through the compromised MSP360 installer, and second, using that access to deploy ScreenConnect for deeper infiltration and control. This dual-RMM (Remote Monitoring and Management) approach underscores the evolving tactics of cybercriminals who are adept at exploiting legitimate software infrastructure for their illicit objectives. Organizations are advised to review their security protocols and user awareness training to mitigate the risks associated with these types of attacks. The effectiveness of this attack relies heavily on the social engineering aspect, making employee education on identifying phishing attempts paramount. The legitimate nature of MSP360 and ScreenConnect means that traditional signature-based detection methods might struggle to identify the malicious activity, necessitating a focus on behavioral analysis and anomaly detection within network traffic and endpoint activity. The advisory from Microsoft aims to equip security professionals with the knowledge to identify and defend against these specific attack vectors, emphasizing the importance of verifying software sources and scrutinizing unexpected communications.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next