CSuite Phishing Campaign Exploits Microsoft 365 Accounts and Devices
A recent phishing campaign called CSuite has been targeting Microsoft 365 accounts and employee devices. The attackers use fake business documents and Microsoft sign-in prompts to gain access.
The researchers at ANY.RUN found that the CSuite campaign uses two paths to gain access: one path installs legitimate remote management software under the guise of opening a document, while the other steals credentials or gets users to approve an attacker's Microsoft 365 sign-in.
The lures used by the attackers borrow familiar business names, including Adobe, DocuSign, Zoom and SharePoint. The researchers found that some installers are packaged as document viewers, while others arrive through scripts that fetch the software after a user opens a file.