CSuite Phishing Campaign Hijacks Microsoft 365 Sessions and Installs Remote Access Tools
Researchers at ANY.RUN have identified a phishing campaign, dubbed CSuite, that has been analysed in 351 sandbox submissions, with just over half originating in the United States. Technology, manufacturing, government, and consulting organisations appear to be the most targeted sectors, with additional activity seen in India, the Philippines, Australia, the UK, and Canada.
The campaign uses familiar business lures impersonating Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. Once a victim engages, the attack can take one of two paths. It may deliver installers or simple script files that quietly install legitimate remote management tools such as ScreenConnect or Action1, giving attackers direct access to the victim's device. Alternatively, it can steer victims toward credential-harvesting or device-code phishing pages designed to capture Microsoft 365 logins and active sessions. In one observed case, an Adobe-themed lure led to a script that elevated privileges and installed ScreenConnect within minutes.
Because CSuite can compromise both cloud accounts and physical endpoints, a single successful phishing attempt can escalate into a much larger security incident, including persistent remote access, account takeover, and fraud. Researchers note that response to this threat should not be siloed: security teams need visibility across both identity systems and endpoint activity to catch it early.