Site icon VMVirtualMachine.com

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

By The Hacker News
Publication Date: 2026-09-30 10:45:00

ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure.

By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems.

CSuite Phishing Leads to Both Account and Endpoint Access

CSuite attack chain exposed by ANY.RUN researchers

CSuite starts with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365.

A forged DocuSign envelope in the name of a law firm analyzed inside ANY.RUN’s Interactive Sandbox

From there, the operation can move in two directions. One path delivers installers, archives, or lightweight BAT/VBS droppers that install legitimate management tools such as ScreenConnect or Action1, giving attackers…

Exit mobile version