ANY [.]RUN researchers have traced a US-focused CSuite phishing campaign that, in analysis of 351 sandbox sessions, yielded a majority of submissions from the United States (51%), with exposure concentrated in technology, manufacturing, government and consulting sectors. The operation combines Microsoft 365 session theft with the deployment of remote‑access tools, enabling attackers to extend a phishing incident into credential compromise, ongoing account control and persistent access to business systems.
The attack chain begins with familiar business-themed lures—Adobe, DocuSign, Zoom, Google Meet, Dropbox and Microsoft 365—leading to two possible paths. One delivers installers or lightweight droppers that install legitimate management tools (such as ScreenConnect or Action1) to gain remote access to endpoints. The other pushes credential-harvesting or device-code phishing flows aimed at capturing Microsoft 365 sessions.
In a sandbox instance, an Adobe-themed lure delivered a BAT file that escalated privileges and installed ScreenConnect, illustrating how quickly phishing can translate into remote endpoint access. CSuite therefore enables attackers to target both Microsoft 365 accounts and employee devices, increasing potential impacts from mailbox compromise to persistent access and internal spread.
Security leaders are advised to prioritise end-to-end visibility across identity and endpoints, reduce investigation time, and curb unauthorised remote‑access tooling.