By The Hacker News
Publication Date: 2026-09-30 10:45:00
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure.
By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems.
CSuite Phishing Leads to Both Account and Endpoint Access
![]() |
| CSuite attack chain exposed by ANY.RUN researchers |
CSuite starts with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365.
![]() |
| A forged DocuSign envelope in the name of a law firm analyzed inside ANY.RUN’s Interactive Sandbox |
From there, the operation can move in two directions. One path delivers installers, archives, or lightweight BAT/VBS droppers that install legitimate management tools such as ScreenConnect or Action1, giving attackers…



