Security

Phishing campaigns steal Microsoft 365 sessions and abuse remote-access tools

Researchers describe phishing campaigns that combine stolen Microsoft 365 sessions with remote-access software. One report focuses on CSuite activity targeting US organizations; Microsoft separately reports campaigns using MSP360 RMM to deploy ScreenConnect, creating redundant access channels. The sources describe different campaign details and do not establish that they are the same operation.

Image: Microsoft Security Blog

What we know

Reported by one source

  • ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses; 51% of submissions came from the United States, and the report names technology, manufacturing, government, and consulting organizations as having the highest exposure. — The Hacker News
  • The CSuite campaign combined Microsoft 365 session theft with remote-access tool deployment, according to the report. — The Hacker News
  • Microsoft observed phishing campaigns abusing MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity. — Microsoft Security Blog

Open questions

Coverage 2 publishers

  1. Microsoft Security Blog

    Phishing Abuses RMM Tools for Persistent Access

  2. The Hacker News

    US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

Articles stay on their publishers’ sites; each link opens the original.