What we know
Reported by one source
- ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses; 51% of submissions came from the United States, and the report names technology, manufacturing, government, and consulting organizations as having the highest exposure. — The Hacker News
- The CSuite campaign combined Microsoft 365 session theft with remote-access tool deployment, according to the report. — The Hacker News
- Microsoft observed phishing campaigns abusing MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity. — Microsoft Security Blog
Open questions
- The sources do not establish whether the CSuite campaign and the Microsoft-observed MSP360 RMM activity are connected. — The Hacker News, Microsoft Security Blog
Coverage 2 publishers
Articles stay on their publishers’ sites; each link opens the original.
