Researchers at ANY.RUN have uncovered a targeted phishing campaign aimed at US-based executive teams, exploiting Microsoft 365 sessions and deploying remote management tools for unauthorized access. Over 351 sandbox analyses revealed that 51% of the activity originated from the United States, with significant exposure in the technology, manufacturing, government, and consulting sectors. The CSuite campaign uses familiar business-related lures involving platforms like Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365 to initiate attacks. Attackers employ two main strategies: they either install remote management tools such as ScreenConnect or Action1 to gain remote access to devices, or they engage in credential harvesting and phishing techniques to capture Microsoft 365 session data.

In one instance, an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect, swiftly transforming a phishing attempt into remote endpoint access. This level of control allows attackers not only to compromise business accounts but also to maintain persistent access to employee devices, extending the impact from simple mailbox breaches to broader organizational risks.

The campaign demonstrates a strong concentration in the US, but it has also been observed in India, the Philippines, Australia, the UK, Canada, and other regions. Security leaders are advised to focus on reducing investigation times and enhancing visibility across both identity and endpoint activities. The CSuite campaign's infrastructure is known to change rapidly, necessitating current detection measures and threat intelligence feeds to keep up with evolving threats.

ANY.RUN’s Interactive Sandbox and Threat Intelligence Feeds offer critical insights, enabling analysts to identify recurring patterns, infrastructure relationships, and related activities. These tools assist teams in maintaining updated security controls and reducing the manual workload of threat analysts. By leveraging structured investigation reports, organizations can streamline the escalation of incidents, ensuring a rapid and effective response to this ongoing threat.