[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsZc3Xlxa8jZDWi0ak2WjkiBc3w84-Y7JQepoywj49BI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"9d089c0a-3ef0-4860-af58-d2bd2b02333c","power-bi-abused-to-host-phishing-lures-deploying-rogue-remote-access-tools","e102ad92-7842-476d-98bd-dd7852c4054a","Power BI Abused to Host Phishing Lures Deploying Rogue Remote Access Tools","Attackers exploited the inherent trust in Microsoft's legitimate Power BI domain to host phishing content that bypasses traditional email security filters, demonstrating how threat actors weaponize trusted cloud platforms to evade detection. Once victims interacted with the malicious dashboards, rogue ScreenConnect remote access clients were silently installed, granting attackers persistent, covert footholds on compromised machines. This matters because organizations often whitelist well-known SaaS domains, creating blind spots that attackers deliberately exploit. The use of legitimate remote management tools like ScreenConnect further blurs the line between malicious and authorized activity, making detection significantly harder without robust behavioral monitoring.","**Immediate actions:**\n- Block or alert on unsanctioned ScreenConnect installations by enforcing application allowlisting policies.\n- Audit and restrict outbound connections to remote desktop and RMM tool endpoints not approved by IT.\n\n**Long-term improvements:**\n- Implement a Cloud Access Security Broker (CASB) to monitor and control data flows to and from trusted SaaS platforms like Power BI.\n- Establish an approved Remote Monitoring and Management (RMM) tool policy and enforce it via endpoint management platforms.\n- Conduct regular employee phishing simulation training that includes scenarios involving trusted brand impersonation on legitimate domains.\n\n**Detection measures:**\n- Configure SIEM rules to alert on unexpected ScreenConnect or similar RMM client installations on endpoints.\n- Enable enhanced logging for Power BI access and cross-reference with threat intelligence feeds to identify known malicious dashboard URLs.\n- Monitor for anomalous outbound network connections originating from newly installed remote access software.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-3: Malicious Code Protection","NIST SP 800-53 AC-17: Remote Access","NIST SP 800-53 AU-6: Audit Record Review, Analysis, and Reporting","NIST CSF DE.CM-1: Network Monitoring","NIST CSF PR.AT-1: Security Awareness Training","MITRE ATT&CK T1566: Phishing","MITRE ATT&CK T1219: Remote Access Software","MITRE ATT&CK T1071: Application Layer Protocol","published","2026-10-07T16:20:55.785029+00:00","2026-10-07T16:20:55.433+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F10\u002F07\u002Fpower-bi-phishing-campaign-drops-rogue-screenconnect-clients\u002F?utm_source=rss&utm_medium=rss&utm_campaign=power-bi-phishing-campaign-drops-rogue-screenconnect-clients","power-bi-phishing-campaign-drops-rogue-screenconnect-clients-fe5d1e","Power BI phishing campaign drops rogue ScreenConnect clients",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":44,"name":45,"slug":46,"description":47,"color":48},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]