malware
Published 2026-09-30
Verified 2026-10-01

CSuite phishing (ANY.RUN via THN 30 Sep): M365 session theft + ScreenConnect/Action1 RMM — AU among telemetry countries

The Hacker News (30 September 2026), citing ANY.RUN sandbox research, documents a US-focused “CSuite” phishing operation traced across 351 sandbox analyses (51% of submissions from the United States; also India 18%, with activity in the Philippines, Australia, the United Kingdom, Canada and elsewhere). Lures impersonate Adobe, DocuSign, Zoom, Google Meet, Dropbox and Microsoft 365. Two follow-on paths: (1) installers, archives or lightweight BAT/VBS droppers that install legitimate remote-management tools such as ScreenConnect or Action1 for endpoint remote access; (2) identity theft via credential-harvesting or device-code phishing to capture Microsoft 365 access and active sessions. Example sandbox chain: Adobe-themed lure → BAT elevation → ScreenConnect. Highest exposure sectors in the pivot corpus: technology, manufacturing, government/administration, consulting. Distinct from Microsoft’s 29 Sep MSP360→ScreenConnect phishing write-up already on desk (ms-rmm-phishing-msp360-20260929) — different delivery brand/tool mix and research source. Primary: THN 30 Sep / ANY.RUN.

Product
Microsoft 365 identity + ScreenConnect / Action1 RMM (abused legitimate tools)
Versions
n/a — phishing / living-off-the-land RMM abuse (not a product CVE)
Exploited in Australia?
unknown
Patch to
AU identity/SOC: block/alert on unexpected ScreenConnect/Action1 installs from user paths; prefer phishing-resistant MFA and Conditional Access against device-code / session-cookie theft; treat Adobe/DocuSign/Zoom/M365 lures as high-risk; correlate with ms-rmm-phishing-msp360-20260929 controls. Not a version patch.

Primary: The Hacker News — CSuite phishing steals M365 sessions and deploys RMM (30 Sep 2026) · Vendor: ANY.RUN (research cited by THN)

breaches australia identity cloud