CSuite phishing steals Microsoft 365 sessions, deploys RMM tools
ANY.RUN traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions from the United States. The attack combines Microsoft 365 session theft with remote-access tool deployment, turning a phishing incident into broader account compromise. Technology, manufacturing, government and consulting firms showed the highest exposure.
- 351 sandbox analyses, 51% of submissions from the US
- Steals Microsoft 365 sessions and deploys RMM tools
- Highest exposure: tech, manufacturing, government, consulting
- Phishing escalates to account takeover and fraud
Read next
Security