Two phishing campaigns use remote-management tools to enable follow-on access
Two separately described phishing campaigns combine credential or session compromise with remote-access tools. The CSuite campaign targets Microsoft 365 sessions and deploys RMM tools; Microsoft observed campaigns abusing MSP360 RMM to deploy ScreenConnect. The evidence does not establish that these are the same campaign.
