CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools
Campaign
Summary
Hide ▲
Show ▼
The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and business fraud. Researchers traced the operation across 351 sandbox analyses, with 51% of submissions coming from the United States. The activity uses business-themed lures such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and it is most exposed in technology, manufacturing, government, and consulting organizations. The campaign can turn a single phish into persistent access inside victim environments.
Related Happenings
CSuite phishing exposure concentrates in the United States and key sectors
Trend
H score28
First: 30.09.2026 13:45
Last: 30.09.2026 13:45
Sources 1
How related:
ANY.RUN sandbox telemetry shows a clear US concentration in CSuite activity, with 51% of related submissions coming from the United States.
About this happening:
A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exp...
CSuite phishing exposure concentrates in the United States and key sectors
TrendHow related: ANY.RUN sandbox telemetry shows a clear US concentration in CSuite activity, with 51% of related submissions coming from the United States.
About this happening: A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exp...
N0va phishing campaign targeting North America and Europe
Campaign
H score36
First: 16.09.2026 14:58
Last: 16.09.2026 14:58
Sources 1
About this happening:
N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
N0va phishing campaign targeting North America and Europe
CampaignAbout this happening: N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-accoun...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
Campaign
H score34
First: 13.09.2026 13:11
Last: 13.09.2026 13:11
Sources 1
About this happening:
Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
Microsoft dual phishing campaigns using CEO impersonation and passkey lures
CampaignAbout this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
Campaign
H score34
First: 11.09.2026 20:26
Last: 11.09.2026 20:26
Sources 1
About this happening:
A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
ShinyHunters and Helix passkey-themed Microsoft 365 account compromise campaign
CampaignAbout this happening: A ShinyHunters- and Helix-linked campaign is using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts, exposing Microsoft 3...
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Timeline
-
30.09.2026 13:45 2 articles · 2h ago
CSuite phishing campaign steals Microsoft 365 sessions and installs ScreenConnect
Campaign Scope UpdateThe CSuite phishing campaign uses business-themed lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then branches into credential-harvesting or device-code phishing that can steal Microsoft 365 access and active sessions or deliver BAT/VBS droppers that install ScreenConnect or Action1 for remote endpoint access. The campaign is most exposed in technology, manufacturing, government, and consulting organizations, and telemetry in the report shows 351 sandbox analyses with 51% of related submissions coming from the United States.
Show sources
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access — thehackernews.com — 30.09.2026 13:45
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access — thehackernews.com — 30.09.2026 13:45