CSuite phishing campaign escalates to account and endpoint access
π ANY.RUN researchers traced a US-focused CSuite phishing campaign across hundreds of sandbox analyses, finding 51% of submissions from the United States and heavy exposure in technology, manufacturing, government, and consulting. The operation uses business-themed lures (Adobe, DocuSign, Zoom, Microsoft 365) to either harvest credentials or deliver droppers that install legitimate remote-access tools like ScreenConnect and Action1. This dual path enables mailbox takeover, financial fraud, persistent RMM access, and lateral misuse of trusted identities, expanding impact beyond typical phishing.
