A phishing campaign researchers are tracking as “CSuite” is targeting C-suite executives with two parallel attack paths designed to hijack Microsoft 365 sessions and install remote-monitoring-and-management tools for persistent access to compromised machines.
Two Attack Paths Converge on the Same Executive Targets
The campaign combines credential and device-code phishing aimed at capturing Microsoft 365 access and active sessions with malicious installers or BAT and VBS droppers disguised as familiar business communications from Adobe, DocuSign, Zoom, Google Meet, Dropbox, or Microsoft 365 itself. Both paths are aimed at the same population: executives at technology, manufacturing, government and administration, and consulting organizations, with 51% of observed targeting concentrated in the United States and additional activity identified in India, the Philippines, Australia, the United Kingdom, and Canada. Device-code phishing in particular exploits a legitimate Microsoft 365 sign-in flow designed for devices without an easy way to type a password, tricking a victim into approving what looks like a normal login prompt while the code is actually being used to authorize the attacker’s own session.
ScreenConnect and Action1 Provide Persistent Remote Access
When an endpoint compromise succeeds, the campaign deploys the remote-monitoring-and-management tools ScreenConnect and Action1 to maintain persistent remote access to the victim’s machine. Because both are legitimate RMM products used widely for IT support, their presence on a compromised executive’s machine can blend into normal administrative activity rather than triggering the kind of alert a more obviously malicious tool might generate.
An Adobe-Themed Lure Installed ScreenConnect in Minutes
Researchers documented one case in detail involving an Adobe-themed phishing lure that delivered a BAT file capable of elevating its own privileges and installing ScreenConnect within minutes of the victim opening the phishing page. The speed of that installation — minutes rather than hours — left little window for manual detection once the victim interacted with the lure, underscoring how much of the campaign’s effectiveness depends on automated, fast-executing payloads rather than a prolonged intrusion process.
Analysis Built on 351 Sandboxed Samples, No Attribution Yet
The campaign’s documentation is based on analysis of 351 sandboxed samples, and researchers have not established attribution to any specific named threat actor. Documented outcomes from successful compromises include mailbox takeover, financial fraud, persistent remote access, and lateral spread to colleagues and business partners once an initial executive account or machine is compromised.
Why Targeting Executives Specifically Changes the Risk Calculus
Phishing campaigns that target rank-and-file employees typically aim for a foothold that an attacker then has to work to expand. A campaign built specifically around C-suite executives starts from a position of elevated trust and access: executive mailboxes carry outsized weight in business email compromise schemes because recipients are conditioned to act quickly on instructions that appear to come from senior leadership, and executive accounts frequently have broader access to financial systems, strategic communications, and sensitive organizational data than an average employee account would.
That targeting logic explains why the campaign pairs session hijacking with RMM tool deployment rather than relying on either technique alone. Credential and device-code phishing alone can be undone by a password reset or session revocation once detected, but persistent access through a legitimate RMM tool survives most routine remediation steps unless defenders are specifically looking for unauthorized ScreenConnect or Action1 installations. The combination of a 51%-U.S.-concentrated targeting pattern, a documented minutes-long path from lure to installed RMM access, and the specific choice of executive-level victims suggests a campaign optimized for high-value compromises rather than opportunistic, high-volume targeting. Organizations with executives who have not been specifically trained to recognize device-code phishing prompts, and that lack monitoring for unauthorized RMM installations, remain exposed to exactly the attack chain researchers have now documented.
The campaign’s reliance on well-known brand lures — Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365 — also reflects a deliberate targeting of the communications executives are most likely to receive and act on quickly: document-signing requests, meeting invitations, and file-sharing notifications are routine parts of an executive’s daily inbox, which makes them harder to flag as suspicious than a more generic phishing lure might be. Combined with the lack of attribution to a specific named threat actor, the broad geographic spread of targeting, and the use of two legitimate, commercially available RMM products rather than custom malware, the CSuite campaign appears built for scale and persistence rather than a single, narrowly scoped operation against one organization.
