US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
US-focused CSuite phishing steals Microsoft 365 sessions and installs RMM tools for persistent access.
ANY.RUN researchers tracked a US-focused phishing operation they call CSuite across 351 sandbox analyses, with 51 percent of submissions from the United States and 18 percent from India. Lures impersonate Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. One path delivers archives or BAT and VBS droppers that install legitimate remote-management tools such as ScreenConnect or Action1; another uses credential harvesting or device-code phishing to steal Microsoft 365 access and active sessions. Technology, manufacturing, government, and consulting organizations were among the most exposed, enabling mailbox fraud and persistent endpoint access.