US-Focused CSuite Phishing Campaign Exploits Microsoft 365 Sessions for Broader Business Compromise
A sophisticated phishing campaign, CSuite, has been targeting US-focused businesses across various sectors. According to ANY.RUN researchers, the campaign involves combining Microsoft 365 session theft with remote-access tool deployment, enabling attackers to turn a single successful phishing incident into a broader business compromise.
The attack chain begins with familiar business lures built around Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. From there, the operation can move in two directions: delivering installers or lightweight BAT/VBS droppers that install legitimate management tools for remote access, or targeting identity by capturing Microsoft 365 access and active sessions.
The researchers analyzed 351 sandbox analyses, with 51% coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure to the campaign.