Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Phishers use a fake report on Microsoft's Power BI domain to deliver rogue ScreenConnect clients

Huntress tied one rogue ScreenConnect configuration from a Power BI phishing campaign to 22 more endpoints across separate incidents. For defenders, the thing to hunt is a ScreenConnect client their own IT never deployed.

The Watch · Security desk

How we use AISend a correction

What happened

  • Huntress has seen the same delivery chain, ScreenConnect clients and network indicators hit a handful of endpoints since September 10.
  • The lure is an Outlook email linking to a fake reference document on app.powerbi.com that shows a blurred form and a "Download Reference" button.
  • Pressing the button opens a new browser tab on an attacker-owned site, dailylifeproject[.]site in the case Huntress walked through.
  • A few seconds after that page loads, a script clicks a hidden link that downloads a ScreenConnect installer.

Why it matters

  • constraint Microsoft 365 filters and gateways that trust app.powerbi.com pass the first link. The earliest point where a URL block can work is the attacker-owned page one click later.
  • exposure Sandboxes and scanners running from Microsoft networks, or on anything other than a Windows desktop, can be turned away by the burnsworth variant while a real Windows user gets the installer.
  • precedent One hardcoded Telegram bot credential shared across landing domains ties those sites to a single setup, so a new domain carrying that credential belongs to the same campaign.

Huntress could not obtain the initial email or its lure [4], so the wording that got targets to click is unknown. According to Huntress, earlier Power BI phishing worked from a real dashboard on app.powerbi.com, built under the attacker's own account, usually compromised or throwaway [5]. The attacker embedded a malicious link, set sharing to public and emailed the dashboard to targets [5].

The screening happens on the attacker's own site. The dailylifeproject[.]site page checks the operating system, browser and version, desktop or mobile, user agent, automation indicators, screen size, iframe context and cloud-provider cookies [8]. Visitors who fail are redirected to check.vykyn[.]click/E/ [10]. Huntress calls this anti-analysis filtering, an attempt to weed out scanners and keep researchers from seeing the payload [10]. The burnsworth[.]site variant also collects public IP, ISP, approximate coordinates, device type, full user agent and a UTC timestamp [13].

Victims are reported over Telegram. The page embeds a Telegram Bot API credential and chat identifier, and sends each victim's IP address, geolocation, browser, operating system and download activity to an attacker-controlled bot [9]. Huntress named four landing domains across its incidents [18]. Besides dailylifeproject[.]site, they are burnsworth[.]site, essaywritingservice[.]site and openpediatrics[.]site [11].

The tab pulls down more than one ScreenConnect instance [17]. Once the file lands, the page says the "Reference Verification Form downloaded successfully" and points the target to the Downloads folder [16]. Huntress found the wider spread with a retroactive hunt for the unique ScreenConnect client and configuration tied to one of those instances [2].

What to watch

  • Whether Huntress publishes the ScreenConnect configuration indicators behind the 22-endpoint cluster, so other teams can search their own fleets.
  • New landing domains carrying the same hardcoded Telegram bot credential, a sign the same kit is still in rotation.
  • Any change by Microsoft to public sharing on app.powerbi.com, the setting attackers have used to put their reports in front of outside recipients.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption12
Hype gap0
Incentives
Insufficient
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Starting September 10, Huntress saw a phishing campaign with the same delivery vector, ScreenConnect clients, and network indicators of compromise hit a handful of different endpoints.

    ReportedSupportedSource: HuntressView cited source
  2. [2]

    A retroactive threat hunt showed that the unique ScreenConnect client and configuration associated with one of the RMMs in the attack also impacted 22 other endpoints across separate incidents.

    ReportedSupportedSource: HuntressView cited source
  3. [3]

    The attack started with an Outlook phishing email whose embedded link redirected users to a fake reference document on a legitimate Power BI domain, app.powerbi.com; the page showed a blurred form and prompted targets to 'Download Reference'.

    ReportedSupportedSource: HuntressView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. huntress.com

    1 article · October 7, 2026

    Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories