MSP360 Phishing Attacks Trigger Critical Cybersecurity Alert in Brussels

Lailuma Sadid

Brussels, 1 October, (Brussels Morning Newspaper) – A sophisticated phishing campaign is abusing legitimate remote-management software to establish persistent access to Windows computers, highlighting the growing cybersecurity risk facing businesses and IT administrators. The MSP360 phishing attacks use the legitimate MSP360 remote monitoring and management platform before installing ConnectWise ScreenConnect as a second remote-access tool.

Microsoft security researchers said the campaign was observed in July 2026. Crucially, the activity does not involve exploitation of a reported security vulnerability in MSP360 or ScreenConnect. Instead, attackers rely on social engineering and legitimate software to make malicious activity appear more like normal IT administration.

How the phishing campaign gains remote access

Microsoft said attackers distributed phishing messages built around familiar workplace themes, including meeting invitations, RSVP requests, PDFs and software updates.

Victims were directed to download a legitimate, digitally signed MSP360 RMM installer that was presented using deceptive filenames. The campaign also made use of legitimate cloud services to host or distribute files, further complicating attempts to identify suspicious infrastructure.

Once the victim executed the installer and approved the Windows User Account Control prompt, the legitimate MSP360 components could establish remote-management capabilities on the device.

The attackers subsequently used that access to execute PowerShell commands, retrieve a ScreenConnect MSI installer and deploy the second remote-management platform silently.

Dual-RMM technique strengthens attacker persistence

Installing ScreenConnect provided an additional route into an affected computer. This dual-RMM approach matters because removing the first remote-management platform may not necessarily eliminate an attacker’s access if the second remains active.

Microsoft’s investigation found that attackers could use ScreenConnect to transfer and execute further tools after gaining access. Researchers also observed information-gathering activity and attempts to obtain credentials.

The MSP360 phishing attacks therefore illustrate how legitimate administrative software can be turned against organisations without attackers needing to introduce conventional malware during the initial stage of an intrusion.

MSP360 strengthens safeguards after reported abuse

MSP360 investigated the activity and said accounts connected with the abuse were blocked. The company also strengthened measures designed to prevent misuse of its remote-management platform.

Its response included mandatory business verification requirements before new accounts can customise installer branding or perform remote-management operations through MSP360 RMM.

The company stressed that the campaign involved misuse of legitimate functionality rather than exploitation of a vulnerability in its software.

Why legitimate RMM tools pose a security challenge

Remote monitoring and management platforms are widely used by corporate IT teams and managed service providers to maintain computers, deploy software and troubleshoot systems remotely.

That legitimate role can create a difficult detection problem. Security controls cannot automatically treat every RMM installation as malicious because many organisations depend on the same technology for everyday operations.

Microsoft also identified separate activity involving the legitimate Faronics Deploy Agent as an initial remote-management platform before ScreenConnect was installed. The finding suggests the technique extends beyond a single software provider.

What security teams should do next

Microsoft recommends that organisations maintain clear inventories of authorised RMM applications and restrict remote-management tools that have not been approved by administrators.

Security teams should investigate unexpected RMM installations, unusual PowerShell activity and the appearance of multiple remote-access products on the same endpoint. Combining endpoint, network and identity signals can also help distinguish authorised administration from suspicious activity.

For European businesses and managed service providers, the MSP360 phishing attacks provide another reminder that trusted software can become part of an intrusion chain. Strong application controls, employee awareness and close monitoring of remote-management activity remain important safeguards as attackers increasingly attempt to hide malicious operations within legitimate IT tools.

About Us

Brussels Morning is a daily online newspaper based in Belgium. BM publishes unique and independent coverage on international and European affairs. With a Europe-wide perspective, BM covers policies and politics of the EU, significant Member State developments, and looks at the international agenda with a European perspective.
Share This Article
Lailuma Sadid is a former diplomat in the Islamic Republic of Afghanistan Embassy to the kingdom of Belgium, in charge of NATO. She attended the NATO Training courses and speakers for the events at NATO H-Q in Brussels, and also in Nederland, Germany, Estonia, and Azerbaijan. Sadid has is a former Political Reporter for Pajhwok News Agency, covering the London, Conference in 2006 and Lisbon summit in 2010.
The Brussels Morning Newspaper Logo

Subscribe for Latest Updates