← Back to blog

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

Cybercriminals are constantly finding new ways to trick everyday internet users, and a recent security warning highlights a particularly sneaky tactic. Attackers have started abusing legitimate IT management tools, specifically MSP360 and ScreenConnect, inside phishing emails. Because these are real software programs used by IT professionals every day, security filters often trust them, allowing scammers to slip malicious links and attachments right past your defenses and gain remote access to your device.

The goal of these dual-RMM attacks is to make the fake emails look completely professional and harmless while hiding dangerous remote-monitoring software underneath. If you click the wrong link or download what looks like a routine system update, you could unknowingly hand over control of your computer to a hacker. These sophisticated scams prove that traditional warning signs, like obvious spelling errors or poorly designed graphics, are no longer reliable ways to spot a threat.

To protect yourself from falling victim to these advanced attacks, it is critical to verify any unexpected messages before taking action. If you ever receive a suspicious email asking you to click a link, update software, or log into an account, do not guess whether it is safe. Instead, simply forward the suspicious email to scan@report.mailforensis.com to get a clear, plain-English threat analysis back in seconds, helping you stay safe online without needing a background in cybersecurity.

Got a suspicious email?

Forward it to scan@report.mailforensis.com and get a clear answer in seconds — free.

Try MailForensis free →