US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
CSuite phishing campaign targets US businesses, stealing M365 sessions and deploying RMM tools.
Summary
A US-focused phishing campaign dubbed CSuite has been observed targeting technology, manufacturing, government, and consulting organizations. The campaign employs lures related to common business tools like Adobe and DocuSign to steal Microsoft 365 sessions and deploy legitimate remote management tools (RMMs) such as ScreenConnect or Action1, granting attackers persistent access to endpoints.
Full text
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access The Hacker NewsSep 30, 2026Phishing / Endpoint Security ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems. CSuite Phishing Leads to Both Account and Endpoint Access CSuite attack chain exposed by ANY.RUN researchers CSuite starts with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. A forged DocuSign envelope in the name of a law firm analyzed inside ANY.RUN’s Interactive Sandbox From there, the operation can move in two directions. One path delivers installers, archives, or lightweight BAT/VBS droppers that install legitimate management tools such as ScreenConnect or Action1, giving attackers remote access to the endpoint. The other path targets identity. Victims can be pushed into credential-harvesting or device-code phishing flows designed to capture Microsoft 365 access and active sessions. In one ANY.RUN sandbox session, an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect, showing how quickly a phishing page can turn into remote endpoint access. Adobe-themed lure analyzed inside ANY.RUN sandbox The result is broader than a typical phishing incident: CSuite can give attackers control over both business accounts and employee devices, expanding the potential impact from mailbox compromise to persistent access inside the environment. Reduce the cost of complex incidents by giving teams the context to contain them before access spreads. Strengthen Incident Response CSuite Activity Is Concentrated in the US and Business-Critical Sectors ANY.RUN sandbox telemetry shows a clear US concentration in CSuite activity, with 51% of related submissions coming from the United States. India accounted for 18%, while additional activity appeared across the Philippines, Australia, the United Kingdom, Canada, and other countries. CSuite sandbox submissions by country The campaign also reached several high-value sectors. Technology, manufacturing, government and administration, and consulting were among the most exposed in the pivot corpus. Why CSuite Escalates Fast CSuite can give attackers access to both Microsoft 365 accounts and employee endpoints, creating several ways to turn one successful phish into a wider business incident. Potential outcomes include: Mailbox takeover: Attackers can read ongoing conversations, monitor payment threads, and impersonate trusted employees. Financial fraud: Access to real business correspondence can support invoice manipulation, payment redirection, and supplier fraud. Persistent remote access: Abused RMM tools can keep attackers connected to victim systems after the initial phishing event. Internal spread: Compromised accounts can be used to target colleagues, partners, or customers from a trusted identity. Larger incident scope: Security teams may need to contain stolen sessions and compromised endpoints at the same time, increasing response effort and business disruption. What Security Leaders Should Prioritize Against CSuite CSuite leaves little room for siloed response. Security leaders should focus on shortening investigation time, controlling unauthorized remote-access tooling, and improving visibility across both identity and endpoint activity. Give Analysts Full Attack-Chain Visibility CSuite can move from a convincing business lure to browser activity, script execution, payload delivery, and remote-access installation. Analysts need to reconstruct that sequence rather than judge an incident from a single file or domain. ANY.RUN’s Interactive Sandbox provides visibility into both browser and endpoint activity. In this investigation, in-browser inspection exposed a reference to /m/js/utils.js inside a CSuite lure page. Researchers then used that recurring path to identify related activity across additional sandbox analyses. The JavaScript utils.js file import inside PDF Viewer The same analysis can surface redirects, JavaScript behavior, network requests, PowerShell execution, payload delivery, and RMM installation, giving analysts more context for containment and escalation decisions. Expand Visibility Across Related Threat Activity A single CSuite domain or file may represent only one part of a broader campaign. Analysts should look for recurring paths, infrastructure relationships, and related historical activity instead of treating each indicator in isolation. With ANY.RUN’s Threat Intelligence Lookup, teams can pivot from domains, IPs, URLs, files, or recurring artifacts to related sandbox analyses. One useful pivot from this investigation is: url:"/m/js/utils.js$" ANY.RUN’s Threat Intelligence gives full context into CSuite suspicious activity The query surfaces sandbox activity where the URL ends with /m/js/utils.js, a recurring path observed across related CSuite lure pages. Extend Detection Without Adding More Manual Work CSuite infrastructure can rotate quickly, so manually maintained blocklists can become outdated fast. Detection teams should feed current malicious infrastructure into the security controls they already use rather than relying on analysts to enrich every alert by hand. SOC teams implement TI Feeds for fresh and actionable IOCs ANY.RUN’s Threat Intelligence Feeds can supply fresh malicious IPs, domains, URLs, and other IOCs to SIEM, EDR, firewalls, and other controls. The underlying threat data comes from activity contributed by 16,000+ organizations and 700,000+ security professionals, helping teams keep coverage current as infrastructure changes. Give Tier 1 Clearer Evidence for Escalation Phishing investigations often slow down at the handoff stage. Tier 1 analysts may need to summarize the attack chain, extract indicators, explain the observed behavior, and document why a case needs escalation. ANY.RUN’s Tier 1 report with AI summaries and recommendations for faster handoff Structured investigation reports can reduce that preparation work. ANY.RUN’s Tier 1 reports package sandbox findings into a report with behavioral context, indicators, AI-generated summaries, and recommendations, giving senior analysts a clearer starting point when a case moves up the queue. Build a SOC That’s Up to 3× More Efficient Against Emerging Threats Campaigns like CSuite move quickly across identity and endpoint layers, which can force analysts to spend more time validating alerts, reconstructing attack chains, and deciding what needs escalation. ANY.RUN helps reduce that workload by giving teams faster behavioral context, broader threat intelligence, and structured investigation outputs. Organizations using the solutions have reported: 94% faster threat triage, helping teams reach containment decisions sooner. 20% less Tier 1 investigation time, freeing analyst capacity for more cases without adding headcount. 30% fewer Tier 1 → Tier 2 escalations, reducing pressure on senior analysts and keeping complex cases from becoming bottlenecks. 21 minutes lower MTTR, shortening attacker dwell time and limiting the potential business impact of an incident. Scale Response Without Scaling Headcount. Detect threats in as little as 15 seconds. Cut MTTR by 21 mins per case. Accelerate Threat Response Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Cloud security, endpoint security, Microsoft, Phishing ⚡ Top Stories This Week Roundcube Pre-Auth SQL Injection Flaw A
Indicators of Compromise
- malware — ScreenConnect
- malware — Action1