Thehackernews iconThehackernewsSep 30, 2026 ~7 min source read

CSuite phishing campaign steals Microsoft 365 sessions and installs RMM tools to gain account and endpoint access

ANY.RUN traced 351 sandbox analyses showing a US-focused operation that combines Microsoft 365 session theft with remote-management tool deployment, allowing attackers to move from a single phish to account takeover, persistent endpoint access, and expanded fraud.

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

Share this story

Send the public story page.

Useful takeaways from this story.

Attackers use familiar business lures (Adobe, DocuSign, Zoom, Google Meet, Dropbox, Microsoft 365) to deliver either credential/device-code theft or installers that set up legitimate RMM tools like ScreenConnect or Action1.

Combined identity and endpoint compromise broadens impact: mailbox takeover, payment fraud, persistent remote access, and internal spread are all possible outcomes.

Defenders should reconstruct full attack chains, monitor both identity and endpoint telemetry, and control unauthorized remote-management tooling to shorten investigations and limit lateral spread.

# What happened ANY.RUN researchers analyzed 351 sandbox submissions tied to a phishing operation called CSuite. The telemetry shows the campaign heavily targeted the United States (51% of submissions), with notable activity in India (18%) and additional hits across the Philippines, Australia, the UK, Canada, and others. High-exposure sectors included technology, manufacturing, government and administration, and consulting.

# How the attack works The campaign starts with familiar business-themed lures that look like legitimate requests or documents: forged DocuSign envelopes, Adobe-file viewers, meeting links, or cloud-file prompts. From a single lure the operation takes one of two routes:

  • Identity theft path: victims are directed into credential-harvesting pages or device-code phishing flows designed to capture Microsoft 365 access and active sessions.
  • Endpoint takeover path: phishing pages deliver installers, archives, or lightweight BAT/VBS droppers that escalate privileges and install legitimate remote-management software such as ScreenConnect or Action1. Once installed, those tools give attackers remote control of the endpoint.

ANY.RUN captured examples where an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect, showing how quickly a browser interaction can turn into persistent remote access.

# Why this is more dangerous than ordinary phishing By combining cloud-session theft with RMM installation, CSuite converts a single successful phish into multiple long-term capabilities for the attacker:

  • Mailbox takeover and monitoring of sensitive conversations.
  • Financial fraud through invoice manipulation and payment redirection.
  • Persistent remote access using legitimate management tools.
  • Internal spread via trusted identities to compromise colleagues, partners, or customers.

# Concrete steps defenders should take Focus on visibility across the full attack chain and on controls for remote-management tooling.

  • Control RMM installations: inventory allowed management software, restrict installer execution via application control or privilege restrictions, and block unauthorized administrative tools.
  • Correlate telemetry across endpoint and cloud: combine EDR, identity logs, and sandbox evidence so analysts can decide containment steps that cover both stolen sessions and compromised devices.

# Practical analyst priorities

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app