Find notable cyber news and cases, enriched with sources, timelines, and signals.

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and business fraud. Researchers traced the operation across 351 sandbox analyses, with 51% of submissions coming from the United States. The activity uses business-themed lures such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and it is most exposed in technology, manufacturing, government, and consulting organizations. The campaign can turn a single phish into persistent access inside victim environments.

Related Happenings

CSuite phishing exposure concentrates in the United States and key sectors

Trend
H score28 First: 30.09.2026 13:45 Last: 30.09.2026 13:45 Sources 1

How related: ANY.RUN sandbox telemetry shows a clear US concentration in CSuite activity, with 51% of related submissions coming from the United States.

About this happening: A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exp...

N0va phishing campaign targeting North America and Europe

Campaign
H score36 First: 16.09.2026 14:58 Last: 16.09.2026 14:58 Sources 1

About this happening: N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...

Microsoft dual phishing campaigns using CEO impersonation and passkey lures

Campaign
H score34 First: 13.09.2026 13:11 Last: 13.09.2026 13:11 Sources 1

About this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...

ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign

Campaign
H score34 First: 11.09.2026 20:26 Last: 11.09.2026 20:26 Sources 1

About this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Timeline

  1. 30.09.2026 13:45 2 articles · 2h ago

    CSuite phishing campaign steals Microsoft 365 sessions and installs ScreenConnect

    Campaign Scope Update

    The CSuite phishing campaign uses business-themed lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then branches into credential-harvesting or device-code phishing that can steal Microsoft 365 access and active sessions or deliver BAT/VBS droppers that install ScreenConnect or Action1 for remote endpoint access. The campaign is most exposed in technology, manufacturing, government, and consulting organizations, and telemetry in the report shows 351 sandbox analyses with 51% of related submissions coming from the United States.

    Show sources