VMTech
Discuss a project →

CSuite phishing campaign pairs Microsoft 365 session theft with RMM access

CSuite phishing campaign pairs Microsoft 365 session theft with RMM access

ANY.RUN researchers have traced a US-focused phishing campaign named CSuite across 351 sandbox analyses. Fifty-one percent of related submissions came from the United States, while India accounted for 18%; activity was also observed in the Philippines, Australia, the United Kingdom, Canada and other countries. Technology, manufacturing, government and administration, and consulting were among the sectors with the greatest exposure.

CSuite is notable because it can combine theft of Microsoft 365 access and active sessions with the deployment of legitimate remote monitoring and management tools. The resulting intrusion can extend beyond a compromised mailbox to persistent access on an employee endpoint.

Two routes from a familiar business lure

The campaign uses business-themed lures that imitate Adobe, DocuSign, Zoom, Google Meet, Dropbox and Microsoft 365. ANY.RUN examined a forged DocuSign envelope presented in the name of a law firm, illustrating how the operation adopts routine document and collaboration workflows to engage targets.

One branch of the attack delivers installers, archives or lightweight BAT and VBS droppers. These can install legitimate management products, including ScreenConnect or Action1, to provide remote access to the affected device. In one sandbox session, an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect.

The other branch targets identity. Victims can be directed to credential-harvesting or device-code phishing flows intended to capture Microsoft 365 access and active sessions. With access to genuine business correspondence, attackers may read active conversations, monitor payment threads and impersonate trusted employees.

Why identity and endpoint response must meet

Combining those paths broadens the potential incident. A stolen session may support invoice manipulation, payment redirection or supplier fraud, while an abused RMM tool can retain remote access after the original phishing interaction. Compromised accounts can also be used to approach colleagues, partners or customers from a trusted identity.

ANY.RUN said analysts need to reconstruct the full sequence, from browser activity and redirects through script execution, payload delivery and RMM installation, rather than assess a single file or domain in isolation. During its investigation, in-browser inspection found a reference to /m/js/utils.js in a CSuite lure page. Researchers used the recurring path to identify related activity in other sandbox analyses.

The investigation can also expose JavaScript behaviour, network requests, PowerShell execution and payload delivery. ANY.RUN identified the query url:"/m/js/utils.js$" as a way to surface sandbox activity in which a URL ends with that recurring path. The company also advised looking for related infrastructure and historical artifacts, because a single domain or file can represent only one element of a larger campaign.

Practical implication for security teams

Security leaders should treat suspected CSuite activity as both an identity and an endpoint event. Priorities are shortening investigation time, controlling unauthorized remote-access tools and correlating browser, account and device evidence so that stolen sessions and compromised endpoints can be contained together before access spreads.

#phishing#microsoft365#endpointsecurity#threatintel
Open analytics
On the site 0 views
min read 4 30.09.2026
Instagram

CSuite phishing campaign pairs Microsoft 365 session theft with RMM access

Open the post on Instagram ↗