US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
Sep 30, 2026
Phishing / Endpoint Security
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud, and persistent access to business systems. CSuite Phishing Leads to Both Account and Endpoint Access CSuite attack chain exposed by ANY.RUN researchers CSuite starts with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. A forged DocuSign envelope in the name of a law firm analyzed inside ANY.RUN’s Interactive Sandbox From there, the operation can move in two directions. One path delivers installers, archives, or lightweight BAT/VBS droppers that install legitimate management tools such as ScreenConnect or Action1, giving attackers...