CSuite Phishing Campaign Blends Microsoft 365 Session Theft with RMM Deployment
A sophisticated phishing campaign, dubbed CSuite, is targeting US-based C-suite executives, combining Microsoft 365 session hijacking with the deployment of legitimate remote management tools to achieve broad account and endpoint compromise.

A recent analysis of over 350 sandbox submissions has revealed a targeted phishing campaign, named CSuite, with a significant focus on US-based organizations. Researchers found that 51% of the analyzed attacks originated from the United States, impacting key sectors including technology, manufacturing, government, and consulting. The campaign's dual-pronged approach, which steals Microsoft 365 sessions and deploys Remote Monitoring and Management (RMM) tools, allows attackers to move beyond simple credential theft to gain persistent access to both business accounts and employee endpoints.
The CSuite attack chain begins with familiar business-related lures, often impersonating legitimate services like Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. These initial phishing attempts are designed to trick executives into clicking malicious links or downloading seemingly innocuous files. Once a victim interacts with the lure, the campaign can diverge into two primary paths: identity compromise or endpoint access.
One pathway focuses on stealing user credentials and active Microsoft 365 sessions. This is achieved through credential harvesting pages or device-code phishing flows, which are designed to capture the necessary information to hijack authenticated sessions. This allows attackers to gain access to sensitive corporate communications, financial data, and other critical information stored within the Microsoft 365 ecosystem.
The second pathway involves the deployment of legitimate RMM tools onto the victim's endpoint. These tools, such as ScreenConnect or Action1, are often delivered via installers, archives, or simple script files. By installing these tools, attackers gain direct remote access to the compromised device, enabling them to control the system, exfiltrate data, or deploy further malicious payloads.
The combination of these two attack vectors significantly amplifies the potential impact of a single phishing incident. Attackers can leverage stolen Microsoft 365 sessions to impersonate trusted employees, engage in financial fraud by manipulating payment threads, and spread further within the organization by targeting colleagues and partners. Simultaneously, the RMM tools provide persistent remote access, ensuring that attackers can maintain a foothold even after the initial phishing event is detected.
ANY.RUN's telemetry indicates a strong concentration of CSuite activity within the United States, with India following as a secondary target. The campaign's reach into high-value sectors like technology, government, and consulting suggests a motive of corporate espionage, financial gain, or disruption. The ability to compromise both identity and endpoints presents a complex challenge for security teams, requiring a coordinated response that addresses both account takeovers and device compromise.
Security leaders are advised to focus on reducing incident investigation times, enhancing visibility across both identity and endpoint activities, and controlling the unauthorized deployment of RMM tools. The campaign highlights the need for comprehensive security operations that can reconstruct the full attack chain, from initial lure to payload delivery and remote access installation. Utilizing threat intelligence feeds to keep indicators of compromise current and providing clear escalation paths for Tier 1 analysts are crucial steps in mitigating the risks posed by sophisticated campaigns like CSuite.
This evolving threat landscape underscores the importance of robust security postures that integrate identity protection, endpoint security, and advanced threat detection capabilities. The CSuite campaign serves as a stark reminder that attackers are increasingly adept at leveraging legitimate tools and services to achieve their malicious objectives, demanding continuous vigilance and adaptation from cybersecurity professionals.