Essential Insights
- Cyber actors distribute malicious MSP360 and Faronics Deploy installer files via phishing emails, disguising them as legitimate meeting invites or documents to gain initial access.
- Once executed, these installers deploy DLLs, escalate privileges, and establish persistent remote access through MSP360 and ScreenConnect, blending malicious activity within normal admin workflows.
- The attackers leverage multiple RMM tools to maintain redundant remote channels, evade detection, and facilitate ongoing data theft and credential compromise on targeted endpoints.
Threat Overview, Techniques, and Targets
The threat involves attackers abusing MSP360 Remote Monitoring and Management (RMM) software to gain access to devices. They send phishing emails that include fake meeting invitations, PDFs, or software update prompts. When the recipients open and run the malicious installer, it appears legitimate but is actually malicious. The installer uses trusted cloud services like Amazon S3, Dropbox, and GitLab to stage files.
Once the installer is run, it drops multiple DLL files and uses Windows User Account Control (UAC) to run with high privileges. It then establishes persistent access by installing MSP360 and uses PowerShell commands to stealthily install ScreenConnect. The attacker also creates registry entries and Windows services to ensure the malware restarts automatically. Additionally, they change Windows Firewall rules to allow remote connections through MSP360 on specific ports.
The attack targets organizations that rely on RMM tools for remote management. These may include managed service providers (MSPs) and their clients, especially small to medium-sized businesses that use remote tools for support and maintenance.
Impact, Security Implications, and Remediation Guidance
This attack allows threat actors to maintain persistent, stealthy access to compromised devices. They can transfer additional malicious files, gather information, and steal credentials. The use of legitimate RMM tools such as MSP360 and ScreenConnect helps attackers hide their activity amidst normal network operations.
The security risk is significant because these tools are trusted and often overlooked by security defenses. Attackers can use these channels to conduct further malicious activities without raising suspicion.
To protect against this threat, organizations should obtain remediation guidance from the relevant vendors or cybersecurity authorities. It is important to review and update security policies, monitor network traffic for unusual activity, and ensure timely application of security patches. If you suspect infection, consult with vendors like MSP360 or ScreenConnect for specific recovery steps.
Discover More Technology Insights
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
