ผู้โจมตีใช้ MSP360 และ ScreenConnect ในการโจมตีทางฟิชชิ่ง Cybersecurity Threat: MSP360 and ScreenConnect Phishing Attacks

ผู้โจมตีใช้ MSP360 และ ScreenConnect ในการโจมตีฟิชชิ่ง การหลอกลวงแบบโซเชียลเพื่อเข้าถึงรีโมต
Attackers exploit MSP360 and ScreenConnect in phishing attacks, leveraging social engineering for remote access.
การโจมตี RMM คู่: ภัยคุกคามยุคใหม่
ไมโครซอฟต์เผยว่าแคมเปญฟิชชิ่งใหม่กำลังแพร่กระจายอินสตอลเลอร์ของซอฟต์แวร์ MSP360 Remote Monitoring and Management (RMM) โดยใช้มุกเชิญประชุมผ่านอีเมลที่หลอกลวงอัพเดตซอฟต์แวร์และอื่น ๆ เมื่อซอฟต์แวร์นี้ถูกเรียกใช้ มันจะตั้งค่าการเข้าถึงรีโมตที่ถูกต้องตามกฎหมายบนอุปกรณ์ที่ได้รับผลกระทบและอนุญาตให้ผู้โจมตีเข้าถึงในขั้นเริ่มต้น
การเข้าถึงในขั้นเริ่มต้นนี้ถูกใช้ในการดาวน์โหลดและติดตั้งโปรแกรมหน้าจอรีโมตที่ชื่อ ConnectWise ScreenConnect ทำให้ผู้โจมตีมีช่องทางการเข้าถึงรีโมตเพิ่มเติมเพื่อรวบรวมข้อมูลและเข้าถึงข้อมูลประจำตัวของผู้ใช้ การโจมตีนี้ยังไม่ได้ถูกเชื่อมโยงกับกลุ่มผู้โจมตีใด ๆ
วิธีการโจมตีและการหลอกลวง
การโจมตีนี้เริ่มต้นจากอีเมลฟิชชิ่งที่แจกจ่ายไฟล์อินสตอลเลอร์ที่เป็นของ MSP360 RMM เวอร์ชัน 2.5.0.67 ซึ่งมีการปลอมชื่อไฟล์ เช่น `VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe` หรือ `PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_ oid[redacted].exe` ไฟล์เหล่านี้ถูกจัดเตรียมบนโครงสร้างพื้นฐานที่ผู้โจมตีควบคุม รวมถึงบริการคลาวด์ที่ถูกต้องตามกฎหมายเช่น Amazon S3, Cloudflare R2, Dropbox,
เทคนิคการดำเนินการ
เมื่อผู้ใช้เรียกใช้ไฟล์อินสตอลเลอร์ ไฟล์จะลงททรบบการติดตั้ง DLL หลายตัว และรีสตาร์ทตัวเองผ่าน "Windows User Account Control (UAC)" เพื่อทำงานในบริบทที่มีสิทธิที่สูงขึ้นและใช้ MSP360 ในการติดตั้งการควบคุมระยะไกล
เบื้องหลัง MSP360 และ ScreenConnect
MSP360 ก่อตั้งขึ้นและพัฒนาในปี 2008 เมื่อตอนที่องค์กรต้องการเครื่องมือการจัดการระยะไกลที่ปลอดภัยและใช้งานง่าย ตัวซอฟต์แวร์ถูกพัฒนาในภาษา C# และเป็นหนึ่งในเครื่องมือ RMM ที่เป็นที่นิยมในปัจจุบัน ScreenConnect ตอนนี้เป็นส่วนหนึ่งของ ConnectWise Platform ซึ่งเป็นแพลตฟอร์มที่รวมเครื่องมือการบริหารจัดการและการตรวจสอบ ขณะที่ ConnectWise ก่อตั้งขึ้นในปี 1982 และเป็นผู้นำด้านการสนับสนุนการบริหารจัดการเทคโนโลยี
วิธีป้องกัน
เพื่อป้องกันภัยคุกคามจาก RMM คู่ องค์กรควรตรวจสอบและกรองอีเมลที่เข้ามาอย่างใกล้ชิดและระมัดระวังในการดาวน์โหลดซอฟต์แวร์ นอกจากนี้ควรสำรองข้อมูลสำคัญและตรวจสอบการตั้งค่าการควบคุมการเข้าถึงรีโมตอย่างสม่ำเสมอ
ที่มา: The Hacker News — https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
Dual-RMM Attacks: A New Cyber Threat
Microsoft has reported phishing campaigns distributing installers for MSP360 Remote Monitoring and Management (RMM) software using deceptive themes like meeting invitations, software updates, and more. Once executed, these installers create legitimate remote management access on affected devices, allowing attackers initial control.
This access is exploited to download and install ConnectWise ScreenConnect, providing attackers with an additional remote access avenue to compromised systems, facilitating information collection and credential theft. No specific threat actor has been tied to these activities.
The Deceptive Strategy
The attack begins with phishing emails distributing a signed installer of MSP360 RMM version 2.5.0.67, masqueraded with names like `VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe` or `PDF Reader & Editor the Adobe Acrobatte_rmm_v2.5.0.67_oid[redacted].exe`. These are hosted on attacker-controlled infrastructure and legitimate cloud services like Amazon S3, Cloudflare R2, and Dropbox.
Technical Mechanism
Once launched, the installer drops multiple DLLs and invokes the Windows User Account Control (UAC) enhancement to run with elevated privileges. It deploys MSP360 to maintain persistent access, leveraging the RMM tool to stealthily install ScreenConnect.
Background on MSP360 and ScreenConnect
MSP360 was established in 2008 to meet the demand for secure and user-friendly remote management tools. The software is developed in C# and has become a highly popular RMM tool. ScreenConnect is part of the ConnectWise Platform, which offers comprehensive administrative tools. ConnectWise, founded in 1982, is a leader in providing technology management support.
Recommendations for Protection
To defend against dual-RMM threats, organizations should rigorously monitor and filter incoming emails and exercise caution when downloading software. It’s crucial to back up key data and regularly review remote access control settings.
Source: The Hacker News — https://thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.html
ที่มา:Source: thehackernews.com/2026/09/attackers-abuse-msp360-to-deploy.h
เกี่ยวกับผู้เผยแพร่About the publisher
- ผู้เขียนAuthor
- Oneable Team
- บริษัทCompany
- Oneable — AI-Powered Software Development Agency
- ความเชี่ยวชาญExpertise
- LLM & RAG, AI Agent, Web/Mobile, MLOps
- ติดต่อContact
- www.oneable.co.th/contact