CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations

· Original article ↗

Summary

ANY.RUN researchers detail CSuite, a campaign combining business-themed phishing, Microsoft 365 credential and session theft, device-code attacks, and legitimate remote-management tools to gain access to accounts and endpoints.

Key points

  • The financially motivated operation was observed from February to September 3, 2026, targeting organizations in the US, Europe, and other regions. US organizations accounted for 60% of identified victim organizations.
  • Lures impersonating services such as Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 delivered credential-harvesting pages, device-code flows, or scripts and installers.
  • Device-code phishing directs victims to Microsoft's legitimate device-login page; entering the attacker-provided code authorizes an OAuth request and gives operators access and refresh tokens.
  • The campaign also deploys legitimate remote- and endpoint-management agents, including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect, to gain control of Windows devices.
  • Some ScreenConnect installations register a credential provider and add an authentication package to LSA, enabling interactive-logon credential capture and persistence at boot.
  • Researchers linked the campaign's phishing and remote-access activity through shared infrastructure, tooling, domains, and operator accounts; the report describes 38 domains in the panel registry.
  • Defenders should investigate suspicious device-code sign-ins and Microsoft 365 sessions alongside unexpected management-agent installations; the report recommends revoking sessions and tokens, reviewing OAuth grants and mailbox rules, and removing unauthorized agents.

Article Details

Attack Vectors
  • Adobe Document Cloud invitations and other business-themed phishing messages direct victims to counterfeit document viewers, credential pages, or management-agent downloads.
  • A redirector routes visitors to Microsoft, Google, or generic credential-capture flows based on the email address they enter.
  • Device-code lures instruct victims to enter an attacker-initiated code on Microsoft's legitimate sign-in page, granting the operator access and refresh tokens.
  • Batch and VBS droppers elevate privileges and install legitimate remote-management agents enrolled in operator-controlled tenants.
  • The phishing kit filters automated visitors using browser, address, geographic, interaction, and reCAPTCHA checks.
Defensive Notes
  • Analyze suspicious links and files in an isolated environment before users interact with them.
  • Correlate unexpected Microsoft 365 sessions and device-code authentication with new management-agent installations.
  • If account compromise is suspected, revoke active sessions and tokens, review OAuth grants and mailbox rules, and investigate activity through the affected account.
  • Remove unauthorized management agents and check affected endpoints for persistence.
  • Pivot on recurring kit paths and lure patterns as well as current domains and addresses, because CSuite rotates infrastructure.

Indicators of compromise

TypeIndicatorContext
DOMAINallshore-io[.]camCampaign lure host in the panel registry.
DOMAINambitiousaboutautismorguk[.]comGroup-registered lookalike domain used for a credential-verification stage.
DOMAINarubanetworks-inc[.]comAffiliate-operated host for document and meeting lures.
DOMAINaviationpioneers[.]infoCampaign redirector in the panel registry.
DOMAINcellumbio[.]comSending domain for the licensing-themed lure email.
DOMAINcheckingweb[.]netCounterfeit PDF viewer serving the licensing-themed batch dropper.
DOMAINconferenceuniverses[.]buzzHost listed among the article's highest-value campaign indicators.
DOMAINcorporate-sync-gate[.]netCampaign redirect destination, including for Google-account visitors.
DOMAINcoxnetwork[.]topDocuSign-themed host serving the PHP phishing build.
DOMAINdocseed[.]onlineCampaign lure host in the panel registry.
DOMAINdocseedn[.]onlineCampaign lure host in the panel registry.
DOMAINdocsendsr[.]onlineCampaign lure host; an observed page used an Adobe-themed device-code flow.
DOMAINdocumentationreviewdocument2026review[.]sbsCampaign redirector in the panel registry.
DOMAINdocumentensono[.]sbsObserved voicemail-themed device-code phishing host.
DOMAINdocumentsonitustechnologies[.]sbsCampaign redirector in the panel registry.
DOMAINdocuread[.]imDocuSign-themed host serving the PHP phishing build.
DOMAINdownloaddocumentcontechbuilding[.]sbsCampaign redirector in the panel registry.
DOMAINemsafetoproceedtaward[.]topCampaign lure domain in the panel registry.
DOMAINescrowadmin[.]com[.]auCompromised Australian site hosting a deployment of the credential-phishing kit.
DOMAINexpressdocumentdelivery[.]orgCampaign lure host in the panel registry.
DOMAINfincapitalxcom[.]cfdCampaign lure host in the panel registry.
DOMAINgddfzxa[.]onlineCampaign lure pages and payload archives; also listed in the panel registry.
DOMAINgiiro[.]netCampaign lure host in the panel registry.
DOMAINgreaterheights[.]sbsCertificate-covered domain on the hosting used for operator lures and payloads.
DOMAINgreenbullet[.]baHost fronting the account used for operator lure pages and payloads.
DOMAINkeepsecurepasserword[.]camCampaign lure host in the panel registry.
DOMAINlegacy-bridge-node[.]netPost-capture redirect shared between two panels.
DOMAINlocalcontex[.]onlineHost serving campaign management-agent installers.
DOMAINmaillive[.]sbsCSuite panel administration host and device-code landing page.
DOMAINmmswerod[.]sbsCertificate-covered domain on the hosting used for operator lures and payloads.
DOMAINnetcoxweb[.]topDocuSign-themed host serving the PHP phishing build.
DOMAINpdfsecurtoview[.]cfdCampaign redirector in the panel registry.
DOMAINpdfsecurtoview[.]infoCampaign redirector in the panel registry.
DOMAINpdfsecurtoview[.]sbsCampaign redirector that routes visitors after they enter an email address.
DOMAINpdfsecurtoview365[.]cfdCampaign redirector in the panel registry.
DOMAINpdfsecurtoview365[.]sbsCampaign lure host and destination for redirected Microsoft-account visitors.
DOMAINpdfsecurtoviewothers[.]cfdDomain assigned to the Chameleon credential harvester.
DOMAINpdfsecurtoviewothers[.]sbsDomain assigned to the Chameleon credential harvester.
DOMAINpdfsecurtoviewsuite[.]sbsCampaign lure host in the panel registry.
DOMAINpikecac[.]cfdCampaign lure host in the panel registry.
DOMAINqrcoderuser[.]cfdCampaign lure host in the panel registry.
DOMAINselectivelife01[.]sbsCampaign lure host in the panel registry.
DOMAINselectivelife03[.]sbsObserved SharePoint-themed device-code phishing host.
DOMAINsharepointer-dr[.]comAffiliate-operated host for document and meeting lures.
DOMAINsharerpoint[.]camCampaign lure host in the panel registry.
DOMAINsolarengyloanfunds[.]comGroup-registered lookalike domain used for a credential-verification stage.
DOMAINstubborn-academy[.]icuCampaign address validator.
DOMAINusoffweb69[.]topDocuSign-themed host serving the PHP phishing build.
DOMAINvoicermailsmessager[.]camCampaign lure host in the panel registry.
DOMAINzerichoproject[.]orgHost listed among the article's highest-value campaign indicators.
HOSTNAMEdoc[.]lauraice[.]xyzDocuSign-themed host serving the PHP phishing build.
HOSTNAMEdocusign[.]web-viewww[.]esDocuSign-themed host serving the PHP phishing build.
HOSTNAMEfile[.]shared[.]cnrv[.]techMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEfile[.]shared[.]m36s[.]siteMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEfile[.]shared[.]myscript[.]sbsMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEghs[.]coorpes[.]comCertificate-covered hostname on the hosting used for operator lures and payloads.
HOSTNAMEinstance-t7o41i-relay[.]screenconnect[.]comScreenConnect relay bound to a client used for remote control.
HOSTNAMEloq[.]file[.]cnrv[.]onlineMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEm36nx[.]file[.]cnrv[.]onlineMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEmail[.]boratlongyear[.]comCampaign lure-mail sending relay.
HOSTNAMEmail[.]wirsann[.]comCampaign lure-mail sending relay.
HOSTNAMEshared[.]file[.]cnrv[.]techMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEshared[.]file[.]nn365[.]cloudMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEshared[.]note[.]nn365[.]cloudMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEsqrd[.]m365[.]sharedfile[.]onlineMicrosoft 365 document lure host identified in campaign indicators.
HOSTNAMEsqrd[.]m36s[.]sharedfile[.]techMicrosoft 365 document lure host identified in campaign indicators.
IPV4102[.]67[.]5[.]132Address identified as an operator address.
IPV4102[.]88[.]167[.]38Address identified as an operator address.
IPV4141[.]133[.]174[.]208Campaign lure-mail sending relay address.
IPV4155[.]254[.]26[.]180Self-hosted ScreenConnect relay used by a staged installer; the indicator list specifies port 8041.
IPV4185[.]174[.]102[.]34GSuite panel address.
IPV4188[.]127[.]227[.]18Campaign lure-mail sending relay address.
IPV4190[.]123[.]46[.]122Kit origin server.
IPV4191[.]101[.]130[.]42Address identified as an operator address.
IPV4207[.]189[.]19[.]40Remote-desktop foothold used for operator work; the article specifies port 26688.
IPV4212[.]189[.]40[.]73Self-hosted ScreenConnect relay used by a staged installer; the indicator list specifies port 8041.
IPV431[.]57[.]147[.]133Address identified as an operator address.
IPV431[.]57[.]38[.]60Address identified as an operator address.
IPV464[.]204[.]180[.]203Self-hosted ScreenConnect server used by a batch dropper; the article specifies port 8040.
IPV491[.]92[.]41[.]114Self-hosted ScreenConnect relay used by staged installers; the article specifies port 8041.
SHA25607682ca34a9bf18beb664088e55035a83306b95b31d4aaba242e9d67f8c378a3Campaign lure page A, index.html.
SHA2560d6b451bd58b904e7dd15ce3e28ea129f7f95c9d248944fbdacdf6fb1d2adc99PHP-build settings.php reporting configuration.
SHA2562b89225801591cd223e0cf0b1faa8e7b12e88d6b6bc6ec9f5e715171137553acPHP-build e-sign.php download page.
SHA256375e49680fe4b4a62320bdcfd16b7bd75f6223a15d620c475c6988803b67d416PHP-build index.php visitor-reporting and redirect component.
SHA25638ba6bfe0cc2b7c5ff38f1f698e2c9bfdb52dd7937111967fddf785ba001e1f2Amended_Agreement02026.vbs campaign dropper.
SHA256394d7be5ecbe326062c1de1fb674bdcbb4dbe3ce03b4227994607047b832debdm/js/fingerprint.js browser-fingerprinting module.
SHA2563a8daf4e992ea34b71b259af85d4d12ca52d80b9e2b262bd5aa5922a5a955f9fRebuilt lure page A serving a management agent.
SHA25641734f8e6cc75b66f51638b76780f61a0b21ad9f77586e2665b7ab8d7e131936Adobe-themed Hexnode management-agent installer.
SHA256463786717f51b710dbbb013437141e416b98d810dfaa9f4de90a4c4939bc66b9Syncro agent distributed under Adobe and Dotloop filenames.
SHA2566f62a8380eb5038e253772033c0ebc1ddb951a042c4a1a90ba8755819dc74e53Adobe.ClientSetup.msi staged client configured for relay 155.254.26[.]180.
SHA25674e306072561731adf55afd4de461ec0736ca22c0b458a78e7512b2701341f28m/js/captcha.js challenge and verification module.
SHA2567b03111fa24ce01054332f013b3fe8189d2b61897e7306666c73b086588a64a5PHP-build download.php payload-delivery component.
SHA256842f0236ea2c2b7773054920e7a870e07869c4e99f84bd31ccfd215781b4f267Substituted msvcp140.dll used with the loader.
SHA25690f8e6259ce27592c460d235aff104d7507dfff4e7889c34ab714cdb19944473Adobe Installer V3572.bat dropper for an Action1 agent.
SHA2569a03a0b65b2a2d27b348e583237d512a55f3f8287989abf7ffca0285d5f8e43dQ4_Report062.zip payload archive B.
SHA256a450a84a60ce6646596feb2d6bea4c89a1b5b4e7d6325d5b7c2000982987411cUpdated Service Agreement 2026.bat dropper for a ScreenConnect client.
SHA256a89a31ec605c0ed9cd263cbdea6ee4a2c6502ec81e5b3e8a3c9fb3de945405f9SSAStatement.exe, the renamed Adobe loader in a campaign payload.
SHA256aac51e4016c50a705a26bd56435f0fd9685e53d6bc0cc6034b7370e76d7cb376Staged ScreenConnect client configured for relay 91.92.41[.]114.
SHA256ae7af8159f06a059411411e5e816b415e32213371fb085ced1dc5679a0112c48AdobePdf_Reader.zip payload archive A.
SHA256aefd71902453cc83104aa963d8d9051c875d93ddf40680616e8fa5e68565ea69Staged ScreenConnect client configured for relay 212.189.40[.]73.
SHA256b1e55c9679f9aca94d66fdb08195cf8752f69f1d6896a5b2e60d979fca5a4036Update_6779.bat dropper for a ScreenConnect client.
SHA256b59e7cb539c0b81a58f60d5ca0ed3df62d1856b29076720efbb7dd9411d99eecScreenConnect.ClientSetup.msi remote-management client delivered by the operation.
SHA256c0eb04dcfa745653c466c34978a1f3b4e5041f526be8c2e46b8c722498ca746aShared m/js/utils.js phishing gate.
SHA256c5f7083722fc5bee4e7a7109495348d3731e6b077919a6b679b9f5af885923cdVerification gate from a complete kit deployment.
SHA256d995ea6f1621c29cdd4353cfb8b36cd1336b34bc8b180b73ce52cd939060bf0fAction1 agent distributed under Adobe and Dotloop filenames.
SHA256e769b2b4463e7d39320b65a49183ce4ff8c20459fa183e7b03f02e1b44420eb0Campaign lure page B, Adobe.html.
SHA256eb9274a1fb6064e784f9c0ce95c78007efcadc279d4ffcac13998a45ebf7b49fDocuSign-themed Hexnode management-agent installer.
SHA256fd98c6881cadc47e7d425bbd4b992237a832e69fdfe872a90ba567ed58a148adServed Chameleon credential page.
SHA256fdd171cc26704218b0762a33650c0d1246c42cbe583a858684e1b6ac12b9bbe7PHP-build eDocusign.php blurred-document decoy.
URLhxxps[:]//app[.]action1[.]com/agent/5c2cda44-433f-11f1-9ef8-332f425c6d9a/Windows/agent(My_Organization)[.]msiSpecific agent package in an operator-controlled Action1 tenant fetched by a dropper.
URLhxxps[:]//github[.]com/Ivan3900/test/raw/main/ScreenConnect[.]ClientSetup[.]msiSpecific GitHub-hosted ScreenConnect installer fetched by a campaign batch dropper.
URLhxxps[:]//localcontex[.]online/AdobecloudReader/pdf_Reader_en_install[.]msiManagement-agent payload delivery URL.
URLhxxps[:]//localcontex[.]online/review[.]signal-doc[.]cloud/[.]DocuSign/Campaign delivery path for the DocuSign-themed kit.

MITRE ATT&CK

T1036.005 · Match Legitimate Resource Name or LocationSSAStatement.exe used an Adobe-themed name to appear to be a financial statement.T1056.003 · Web Portal CaptureThe Chameleon credential page collected a victim's password through a counterfeit portal.T1059.001 · PowerShellDroppers used PowerShell to relaunch with elevation and download agent packages.T1059.003 · Windows Command ShellBatch droppers checked administrative rights and launched agent installation.T1090.003 · Multi-hop ProxyCloudflare workers.dev reverse proxies concealed lure-domain origins.T1105 · Ingress Tool TransferDroppers fetched agent packages from an operator-controlled Action1 tenant and staged download locations.T1114.002 · Remote Email CollectionThe operator used a remote-desktop host to access captured mailboxes manually.T1189 · Drive-by CompromiseOn Adobe-themed pages, a synthetic click started a payload download when the page loaded.T1204.002 · Malicious FileCounterfeit viewer instructions prompted victims to open downloaded scripts or installers.T1218.007 · MsiexecA batch dropper passed a remote ScreenConnect MSI URL to msiexec for quiet installation.T1219 · Remote Access ToolsOperator-enrolled ScreenConnect and other legitimate management agents provided remote endpoint access.T1480 · Execution GuardrailsAddress, fingerprint, and country filters restricted who could reach phishing pages.T1497 · Virtualization/Sandbox EvasionThe kit checked for automation and scanners and used a timed resource-exhaustion trap against analysis.T1539 · Steal Web Session CookieThe panel's per-domain capture modes took authenticated Microsoft 365 sessions.T1547.002 · Authentication PackageA ScreenConnect authentication package was appended to LSA to load at boot.T1553.002 · Code SigningThe article reports use of a valid Adobe DigiCert signature on the loader to pass signature and reputation checks.T1556 · Modify Authentication ProcessA registered ScreenConnect credential provider exposed interactive logons to the operator.T1566.002 · Spearphishing LinkAdobe Document Cloud share invitations from hijacked tenants carried phishing links.T1567 · Exfiltration Over Web ServiceLure pages reported visitor details through a messaging bot API.T1574.001 · DLLSSAStatement.exe loaded a substituted msvcp140.dll from its directory to execute attacker code.T1583.001 · DomainsThe operation used registered lure, redirector, harvester, and lookalike domains.T1583.004 · ServerA shared-hosting account held lure pages and payload archives.T1584.004 · ServerThe article reports compromised legitimate websites serving the lure kit.T1585.003 · Cloud AccountsTwo Cloudflare accounts with connected API keys fronted and automated operation domains.T1608.001 · Upload MalwarePayload archives were staged on shared hosting and agent installers in a public code-hosting account.T1621 · Multi-Factor Authentication Request GenerationDevice-code pages led victims to approve an attacker-initiated authentication request.T1656 · ImpersonationThe Chameleon page used logos and a website screenshot to impersonate the target organization's portal.

Vendors

Products

Action1One delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.Adobe Document CloudHijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure.AteraOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.Cloudflare R2Delivery telemetry adds a fifth vendor: PDQConnectAgent_ZoomUpdater.msi, served 46 times from a Cloudflare R2 bucket alongside Zoom_InstallerX64.zip.Cloudflare WorkersHijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure.HexnodeHexnode management agent, 190 MB, Adobe theme Microsoft 365ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools.PDQ ConnectOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.ScreenConnectOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.SyncroOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.

Tools

Countries

Industries

Related Articles