# What happened ANY.RUN researchers analyzed 351 sandbox submissions tied to a phishing operation called CSuite. The telemetry shows the campaign heavily targeted the United States (51% of submissions), with notable activity in India (18%) and additional hits across the Philippines, Australia, the UK, Canada, and others. High-exposure sectors included technology, manufacturing, government and administration, and consulting.
# How the attack works The campaign starts with familiar business-themed lures that look like legitimate requests or documents: forged DocuSign envelopes, Adobe-file viewers, meeting links, or cloud-file prompts. From a single lure the operation takes one of two routes:
- Identity theft path: victims are directed into credential-harvesting pages or device-code phishing flows designed to capture Microsoft 365 access and active sessions.
- Endpoint takeover path: phishing pages deliver installers, archives, or lightweight BAT/VBS droppers that escalate privileges and install legitimate remote-management software such as ScreenConnect or Action1. Once installed, those tools give attackers remote control of the endpoint.
ANY.RUN captured examples where an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect, showing how quickly a browser interaction can turn into persistent remote access.
# Why this is more dangerous than ordinary phishing By combining cloud-session theft with RMM installation, CSuite converts a single successful phish into multiple long-term capabilities for the attacker:
- Mailbox takeover and monitoring of sensitive conversations.
- Financial fraud through invoice manipulation and payment redirection.
- Persistent remote access using legitimate management tools.
- Internal spread via trusted identities to compromise colleagues, partners, or customers.
# Concrete steps defenders should take Focus on visibility across the full attack chain and on controls for remote-management tooling.
- Control RMM installations: inventory allowed management software, restrict installer execution via application control or privilege restrictions, and block unauthorized administrative tools.
- Correlate telemetry across endpoint and cloud: combine EDR, identity logs, and sandbox evidence so analysts can decide containment steps that cover both stolen sessions and compromised devices.
# Practical analyst priorities