
Phishing campaigns steal Microsoft 365 sessions and abuse remote-access tools
Researchers describe phishing campaigns that combine stolen Microsoft 365 sessions with remote-access software. One report focuses on CSuite activity targeting US organizations; Microsoft separately reports campaigns using MSP360 RMM to deploy ScreenConnect, creating redundant access channels. The sources describe different campaign details and do not establish that they are the same operation.