MalwareOct 7, 2026
Power BI phishing campaign drops rogue ScreenConnect clients
Power BI phishing campaign uses rogue ScreenConnect clients for remote access.
Summary
Attackers are leveraging Microsoft Power BI to host phishing lures that bypass email security filters. These lures then deploy multiple rogue ScreenConnect clients on victim machines, establishing persistent remote access. The campaign, observed since September 10th, utilizes public Power BI dashboards on Microsoft's legitimate domain.
Indicators of Compromise
- domain — app.powerbi.com
Entities
Power BI (product)ScreenConnect (product)Microsoft (vendor)