Follow the latest coverage, related explainers and connected technology stories.
Microsoft observed phishing campaigns that distributed a legitimate MSP360 installer under deceptive names, then used it to install ConnectWise ScreenConnect and create two recurring remote-access channels. The company did not observe exploitation of a vulnerability in ScreenConnect; rather, the attackers abused trusted administrative tools to conduct subsequent activities, including information gathering and credential access.
Phishing actors exploited the legitimate Faronics Deploy platform for remote device management to gain administrative access to more than 457 endpoints, then used PowerShell to install ConnectWise ScreenConnect as an additional access channel. Faronics took action after being notified by Huntress, and indicators of the activity declined as of August 21.