Threats · 4h ago
ANY.RUN traced the CSuite phishing campaign across 351 sandbox submissions, and 51% came from the United States. The activity hit technology, manufacturing, government, and consulting organizations, and it split into two access paths: Microsoft 365 session theft and deployment of legitimate remote-management tools such as ScreenConnect and Action1.
The phish uses ordinary business lures, then either steers victims into credential or device-code capture for Microsoft 365, or drops an installer, archive, or BAT/VBS file that puts a trusted remote tool on the endpoint. Because those tools are legitimate, the attacker can look like normal IT activity while keeping remote access to the device and the account.
For Microsoft 365-heavy shops that allow remote-support or RMM software on employee laptops, this means mailbox cleanup alone may not end the incident. If the session is still valid or the remote tool is already installed, the attacker can keep operating from inside the environment and turn one phish into persistent account and endpoint access.
2 sources covering this story
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
CSuite phishing targets Microsoft 365 sessions and deploys remote-access tools, with 51% of 351 sandbox submissions coming from the U.S.
Phishing Abuses RMM Tools for Persistent Access | Microsoft Security Blog
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity
Part of the PlainSec briefing for 2026-09-30