By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Phishing Campaign Targets CSuite, Steals Microsoft 365 Sessions

ANY.RUN researchers have detailed a sophisticated CSuite phishing campaign specifically targeting United States-based executives, as revealed through an analysis of 351 sandbox submissions. This campaign demonstrates a dual-pronged attack strategy that combines the theft of Microsoft 365 session cookies with the deployment of Remote Monitoring and Management (RMM) tools. The primary objective appears to be gaining persistent, unauthorized remote access to compromised systems and sensitive corporate data.
The analysis indicated that 51% of the sandbox submissions originated from the United States, highlighting the campaign's geographic focus. Organizations within the technology, manufacturing, government, and consulting sectors were identified as having the highest exposure to this threat. This concentration suggests that attackers are strategically targeting industries that often handle valuable intellectual property, sensitive government data, or manage critical infrastructure, making them lucrative targets for espionage or financial fraud.
The mechanics of the attack involve tricking CSuite individuals into clicking malicious links or opening infected attachments within phishing emails. Upon successful execution, the attackers aim to steal session cookies for Microsoft 365. These cookies allow attackers to bypass multi-factor authentication and gain direct access to a user's account, including email, cloud storage, and collaboration tools, without needing the user's password. This method of session hijacking is particularly effective as it leverages legitimate authentication tokens that are already established.
Following the session theft, the campaign's secondary objective is to deploy RMM tools. These tools, such as AnyDesk, TeamViewer, or ConnectWise Control, are legitimate software used by IT professionals for remote support and system management. However, when deployed by malicious actors, they provide attackers with deep control over the victim's computer, enabling them to install further malware, exfiltrate data, conduct financial transactions, or pivot to other systems within the corporate network. The combination of stolen Microsoft 365 sessions and RMM tool deployment transforms a single phishing incident into a comprehensive account compromise, significantly increasing the potential for widespread fraud and data breaches.
The ANY.RUN research underscores the evolving tactics of cybercriminals who are increasingly sophisticated in bypassing traditional security measures. By targeting high-privilege accounts within CSuites and leveraging both session hijacking and RMM tools, attackers can achieve a high degree of stealth and operational freedom within victim organizations. This campaign serves as a critical warning for organizations to enhance their endpoint security, employee training on phishing awareness, and implement robust monitoring for anomalous login activities and the unauthorized installation of remote access software.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.