Summaries
Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.
Showing 1-2 of 2 results
| Date | Provider | Score | Summary |
|---|---|---|---|
| 01 Oct 2026, 12:32 AM | The Hacker News | 4.5 | Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft Security Research reported a phishing campaign, detected in July 2026, that delivers a digitally signed MSP360 RMM v2.5.0.67 installer disguised as meeting invites, PDF readers, software updates, and e-card/RSVP lures (e.g. VIP_ECARD_INVITATION_rmm_v2.5.0.67_oid[redacted].exe, SSA.GOV_STATEMENT_rmm_v2.5.0.67_oid[redacted].exe). The installer relaunches itself through the Windows UAC elevation flow, drops DLLs, registers RMM.Agent.exe and RMM.Agent.Launcher.exe as Windows services with Registry autorun entries, and opens inbound UDP port 48678 in Windows Firewall. It then uses MSP360 to run PowerShell that installs a ConnectWise ScreenConnect client as a second, redundant remote-access channel for tool delivery and credential access. Payloads were staged on both attacker infrastructure and legitimate services including Amazon S3, Cloudflare R2, Dropbox, GitLab, and Supabase. Microsoft did not attribute the activity to any known threat actor. Why: The thing that got past defences was a valid vendor signature on a legitimate MSP360 binary, so 'it's signed' is not a trust decision on its own — the detectable signal here is the lure filename pattern (_rmm_v2.5.0.67_oid...) and the combination of an RMM service plus a ScreenConnect install on the same host. If you don't deploy MSP360 RMM anywhere, you can alert or block on RMM.Agent.exe / RMM.Agent.Launcher.exe services, autorun registry entries, and outbound UDP 48678 rather than waiting for an AV signature. If you run any file-hosting or storage product (S3, R2, Dropbox, GitLab, Supabase were all used as staging), treat abuse-reporting and takedown for hosted installers as an operational cost, not an edge case. There is no Malaysia-specific angle in this report, so treat it as a generic endpoint-detection change. |
| 30 Sep 2026, 6:45 PM | The Hacker News | 4.5 | US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a phishing campaign dubbed "CSuite" across 351 sandbox analyses, with 51% of submissions from the United States, 18% from India, and further activity in the Philippines, Australia, the UK, and Canada; technology, manufacturing, government, and consulting showed the highest exposure. Lures impersonate Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and the chain splits two ways: installers, archives, or BAT/VBS droppers that install legitimate remote-management tools such as ScreenConnect or Action1, or credential-harvesting and device-code phishing flows that capture Microsoft 365 access and active sessions. One analyzed session showed an Adobe-themed lure delivering a BAT file that elevated privileges and installed ScreenConnect. Why: The device-code phishing path is the one most startup teams have not locked down: if your Microsoft 365 tenant allows the device-code flow, a lure alone can hand over live sessions without a password prompt, and the RMM path means an endpoint ends up with ScreenConnect or Action1 installed under attacker control. Concretely, check whether your Entra ID conditional access blocks device-code flow, and whether anyone would notice a ScreenConnect or Action1 install on a work laptop — small teams without a SOC typically would not. This is a US-concentrated campaign, so treat it as a check-your-config item rather than an imminent local threat; the text gives no Malaysia-specific figures. |