SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Phishers use a fake report on Microsoft's Power BI domain to deliver rogue ScreenConnect clients
Huntress tied one rogue ScreenConnect configuration from a Power BI phishing campaign to 22 more endpoints across separate incidents. For defenders, the thing to hunt is a ScreenConnect client their own IT never deployed.
The Watch · Security desk
What happened
- Huntress has seen the same delivery chain, ScreenConnect clients and network indicators hit a handful of endpoints since September 10.
- The lure is an Outlook email linking to a fake reference document on app.powerbi.com that shows a blurred form and a "Download Reference" button.
- Pressing the button opens a new browser tab on an attacker-owned site, dailylifeproject[.]site in the case Huntress walked through.
- A few seconds after that page loads, a script clicks a hidden link that downloads a ScreenConnect installer.
Why it matters
- constraint Microsoft 365 filters and gateways that trust app.powerbi.com pass the first link. The earliest point where a URL block can work is the attacker-owned page one click later.
- exposure Sandboxes and scanners running from Microsoft networks, or on anything other than a Windows desktop, can be turned away by the burnsworth variant while a real Windows user gets the installer.
- precedent One hardcoded Telegram bot credential shared across landing domains ties those sites to a single setup, so a new domain carrying that credential belongs to the same campaign.
Huntress could not obtain the initial email or its lure [4], so the wording that got targets to click is unknown. According to Huntress, earlier Power BI phishing worked from a real dashboard on app.powerbi.com, built under the attacker's own account, usually compromised or throwaway [5]. The attacker embedded a malicious link, set sharing to public and emailed the dashboard to targets [5].
The screening happens on the attacker's own site. The dailylifeproject[.]site page checks the operating system, browser and version, desktop or mobile, user agent, automation indicators, screen size, iframe context and cloud-provider cookies [8]. Visitors who fail are redirected to check.vykyn[.]click/E/ [10]. Huntress calls this anti-analysis filtering, an attempt to weed out scanners and keep researchers from seeing the payload [10]. The burnsworth[.]site variant also collects public IP, ISP, approximate coordinates, device type, full user agent and a UTC timestamp [13].
Victims are reported over Telegram. The page embeds a Telegram Bot API credential and chat identifier, and sends each victim's IP address, geolocation, browser, operating system and download activity to an attacker-controlled bot [9]. Huntress named four landing domains across its incidents [18]. Besides dailylifeproject[.]site, they are burnsworth[.]site, essaywritingservice[.]site and openpediatrics[.]site [11].
The tab pulls down more than one ScreenConnect instance [17]. Once the file lands, the page says the "Reference Verification Form downloaded successfully" and points the target to the Downloads folder [16]. Huntress found the wider spread with a retroactive hunt for the unique ScreenConnect client and configuration tied to one of those instances [2].
What to watch
- Whether Huntress publishes the ScreenConnect configuration indicators behind the 22-endpoint cluster, so other teams can search their own fleets.
- New landing domains carrying the same hardcoded Telegram bot credential, a sign the same kit is still in rotation.
- Any change by Microsoft to public sharing on app.powerbi.com, the setting attackers have used to put their reports in front of outside recipients.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption12
- Hype gap0
- Incentives
- Insufficient
- Confidence60
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Starting September 10, Huntress saw a phishing campaign with the same delivery vector, ScreenConnect clients, and network indicators of compromise hit a handful of different endpoints.
- [2]
A retroactive threat hunt showed that the unique ScreenConnect client and configuration associated with one of the RMMs in the attack also impacted 22 other endpoints across separate incidents.
- [3]
The attack started with an Outlook phishing email whose embedded link redirected users to a fake reference document on a legitimate Power BI domain, app.powerbi.com; the page showed a blurred form and prompted targets to 'Download Reference'.
- [4]
Huntress could not obtain the initial phishing email and lure.
- [5]
Threat actors have previously abused Power BI in phishing by creating real dashboards on app.powerbi.com under their own, usually compromised or throwaway, accounts, embedding a malicious link, and setting the dashboard's sharing permissions to public before sending it to targets by email.
- [6]
Because the link points to Microsoft's real Power BI domain, it skirts through Microsoft 365 mail filters and other security gateways that trust this domain.
- [7]
When the target clicked 'Download Reference', a new browser tab opened to dailylifeproject[.]site/S/.
- [8]
The landing page fingerprinted the browser and environment, checking operating system, browser and version, mobile or desktop status, user-agent, automation indicators, screen size, iframe context, and cloud-provider-associated cookies.
- [9]
The landing page embedded a Telegram Bot API credential and chat identifier to report victims' IP addresses, geolocation, browser, operating system and download activity to an attacker-controlled Telegram bot.
- [10]
Visitors who failed the checks were redirected to check.vykyn[.]click/E/; Huntress describes this as anti-analysis and traffic filtering behavior intended to weed out scanners and keep researchers from seeing the payload.
- [11]
Across other incidents, the new browser tab opened to other attacker-controlled domains, including burnsworth[.]site, essaywritingservice[.]site and openpediatrics[.]site.
- [12]
The variant hosted on burnsworth[.]site restricted access to Windows desktop systems and filtered Microsoft or unknown ISPs.
- [13]
The burnsworth[.]site variant collected victims' public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp.
- [14]
The burnsworth[.]site variant reused the same hardcoded Telegram Bot API credential and chat identifier to report its telemetry.
- [15]
The page was configured to delay the automatic download: after a few seconds, a script programmatically clicked a hidden download link leading to a malicious ScreenConnect installer.
- [16]
The webpage displayed a notification stating the 'Reference Verification Form downloaded successfully' and told targets to view it in their Downloads folder.
- [17]
The new browser tab kicked off the download of multiple malicious ScreenConnect remote monitoring and management instances.
- [18]
Huntress named four attacker landing domains across the incidents it described.
Sources
1 independent publisher whose own reporting we read for this story.
- huntress.comPhishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Trusted Platform AbuseFollow
- PhishingFollow
- Remote management tool abuseFollow
Entities
- HuntressFollow
- Microsoft Power BIFollow
- ScreenConnect (ConnectWise Control)Follow
- Microsoft 365Follow
- Telegram Bot APIFollow