security: Phishing Abuses RMM Tools for Persistent Access
Microsoft Security Blog
2026-09-29
Microsoft reported phishing campaigns that abused MSP360 RMM to deploy ScreenConnect and establish redundant remote-access channels for later malicious activity. The focus is on persistence and follow-on access rather than initial compromise alone.