US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
- ID
- 30272
- Status
- summarized
- Published
- 30 Sep 2026, 6:45 PM
- Fetched
- 30 Sep 2026, 8:55 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 30 Sep 2026, 8:57 PM
- Tags
- Audience
- developerssaas_founders
What happened
ANY.RUN researchers traced a phishing campaign dubbed "CSuite" across 351 sandbox analyses, with 51% of submissions from the United States, 18% from India, and further activity in the Philippines, Australia, the UK, and Canada; technology, manufacturing, government, and consulting showed the highest exposure. Lures impersonate Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and the chain splits two ways: installers, archives, or BAT/VBS droppers that install legitimate remote-management tools such as ScreenConnect or Action1, or credential-harvesting and device-code phishing flows that capture Microsoft 365 access and active sessions. One analyzed session showed an Adobe-themed lure delivering a BAT file that elevated privileges and installed ScreenConnect.
Why it matters
The device-code phishing path is the one most startup teams have not locked down: if your Microsoft 365 tenant allows the device-code flow, a lure alone can hand over live sessions without a password prompt, and the RMM path means an endpoint ends up with ScreenConnect or Action1 installed under attacker control. Concretely, check whether your Entra ID conditional access blocks device-code flow, and whether anyone would notice a ScreenConnect or Action1 install on a work laptop — small teams without a SOC typically would not. This is a US-concentrated campaign, so treat it as a check-your-config item rather than an imminent local threat; the text gives no Malaysia-specific figures.
Discussion angle
Device-code phishing versus standard credential phishing: why the device-code flow bypasses MFA expectations, and what a one-person ops team can actually restrict in Entra ID this week without breaking legitimate tooling.