securityonline.info 9 Oct 2026, 06:15 UTC

Phishing campaign abuses Power BI pages to install rogue ScreenConnect clients

Phishing campaign abuses Power BI pages to install rogue ScreenConnect clients
CyberSIXT Evidence Panel Source marked as original reporting

A phishing operation has been observed abusing Microsoft Power BI to install rogue ScreenConnect remote access clients. In this campaign, attackers hosted a fake document on a public Power BI page that appeared legitimate to email filters. Recipients who clicked a “Download Reference” link were taken to a site that performed browser and device fingerprinting before guiding some users to a decoy page. The technique allowed the attackers to bypass certain security controls and deliver a ScreenConnect installer to targeted endpoints.

The infection chain features a two-stage remote access setup. First, an initial ScreenConnect client is installed, followed by a second client connected to a different server. In at least one case, the first client was removed after the second was installed, likely to evade detection. The attackers also deployed a tool to hide their activity and, in at least one incident, created a scheduled task to rerun the script every two minutes.

Victims’ IP, location, browser and OS data were sent to a Telegram bot, enabling command-and-control, while the rogue clients granted full remote access. Huntress notes that no confirmed data exfiltration was reported. The campaign appears to reflect a broader trend of dual remote-management channels, with Microsoft noting a similar MSP360- ScreenConnect pairing in a separate phishing wave.

For Defence, researchers recommend restricting remote management tools to approved instances, detecting new ScreenConnect installs, investigating multiple RMM clients on a single endpoint, monitoring for remote-access scheduled tasks, and training users to report suspicious trusted-looking links.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline