Skip to content

Security1 publisher2 min readPublished

CSuite phishing splits between Microsoft 365 session theft and remote-management installs

ANY.RUN tied 351 sandbox analyses to CSuite, a phishing operation that steals Microsoft 365 sessions or installs ScreenConnect or Action1 for remote access. Resetting credentials leaves the remote-access half of an intrusion in place.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying CSuite phishing splits between Microsoft 365 session theft and remote-management installs
Generated illustration

What happened

  • The lures are familiar business themes built around Adobe, DocuSign, Zoom, Google Meet, Dropbox and Microsoft 365.
  • In one ANY.RUN sandbox session, an Adobe-themed lure delivered a BAT file that elevated privileges and then installed ScreenConnect.
  • The United States accounted for 51% of related submissions and India for 18%, with more from the Philippines, Australia, the UK and Canada.
  • Technology, manufacturing, government and administration, and consulting organisations were among the most exposed sectors.
  • Researchers found a reference to /m/js/utils.js inside a lure page and used that recurring path to locate related analyses.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Organisations that run ScreenConnect or Action1 legitimately need an inventory of sanctioned installs, because the attacker's copy is the same product.
  • exposure Finance workflows are exposed once a mailbox falls, because real correspondence gives the operators what they need for invoice manipulation and payment redirection.
  • capability A hijacked Microsoft 365 account lets the operators phish colleagues, partners and customers from an identity those people already trust.

Both paths, as ANY.RUN describes them, begin with a victim acting on a lure, and neither relies on a software flaw [5][6]. The technical bar is low. The operators need the victim to run a file or complete a sign-in flow [5][6]. On the endpoint side the delivery is installers, archives, or small BAT and VBS droppers, and the payload is a legitimate management product such as ScreenConnect or Action1 [5].

The identity side goes after more than passwords. According to ANY.RUN, victims are pushed into credential-harvesting pages or device-code phishing flows built to capture Microsoft 365 access and active sessions [6].

The two routes branch from the same lure [16]. An intrusion that takes the endpoint route does not need a harvested password at all [5][16]. ANY.RUN says abused RMM tools can keep attackers connected to victim systems after the initial phishing event [11]. It also says security teams may need to contain stolen sessions and compromised endpoints at the same time [13].

The scale figures come from ANY.RUN's own sandbox telemetry, and the write-up promotes the company's Interactive Sandbox and Threat Intelligence Lookup products [15]. The 51% US share counts where related submissions came from [2]. Submission origin shows where someone uploaded a sample, so it is at best a proxy for where the targets sit. US and Indian submissions together make up 69% of the set [1].

The 351 analyses describe one repeatable operation with a wide footprint [1][2]. The write-up does not name who runs CSuite, say when the activity started, count confirmed compromises, or show the operators changing tactics over time [1].

What to watch

  • Publication of CSuite indicators beyond the /m/js/utils.js path, such as lure domains and the ScreenConnect or Action1 instances the droppers connect to.
  • Attribution of CSuite to a named group, to settle whether one crew runs it or several share the lure pages.
  • Fraud cases, invoice redirection in particular, traced back to a CSuite lure.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories