Reports describe phishing campaigns using stolen Microsoft 365 sessions and remote-access tools
Two reports describe phishing activity involving remote-management tools, but they cover different campaign details. One reports CSuite phishing that steals Microsoft 365 sessions and deploys remote-access tools; Microsoft separately reports abuse of MSP360 RMM to deploy ScreenConnect for redundant access. The sources do not establish that these are the same campaign.
