# Microsoft warns phishing attacks install two remote administration tools

_Published Wednesday, September 30, 2026 at 3:11 PM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft warns phishing attacks install two remote administration tools — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOOpLuI3TSRRvKO7zux2AsJKVNjC36RcaAJCYelekCSQRhpMSABekI8kmMGLZRBZN2biNqDGyKYY_0AqsXb2PMKS6M3sjeLBlt7UQ_IWhXPQ3_q9DGhetIgFeGkF1d_ZE-l2HZPTDID5FkqdLsv3G_wJ-Yckb-Q2I6FdCLo3-AS-pPbCIDRfgFiRzofpaA/s1700-nu-rw-lo-l85-e365/windows-rmm.jpg)

Microsoft has warned that phishing campaigns use deceptive meeting invitations, PDF lures and software update prompts to install legitimate MSP360 remote management software, then add ConnectWise ScreenConnect as a second access channel. The Hacker News reports that Microsoft detected the intrusion chain in July 2026.

Attackers use MSP360 to execute PowerShell and install ScreenConnect, then transfer tools and collect information and credentials. The installer establishes persistence through Windows services and automatic startup entries. Microsoft also observed attacks substituting Faronics Deploy Agent for MSP360. The activity has not been attributed to a known threat actor or group.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html)

---
Canonical: https://techandbusiness.org/newswire/DCrM4KUDPhiUr7sur_PaIP
Published: 2026-09-30T19:11:42.486Z
Story chronology: 2026-09-30T16:32:59.000Z
Retrieved: 2026-09-30T21:22:32.241Z
Publisher: Tech & Business (techandbusiness.org)
