Full Report
A recent phishing campaign abused Microsoft Power BI links to deliver multiple rogue ScreenConnect clients.
Analysis Summary
# Tool/Technique: Power BI Phishing to Rogue RMM Deployment
## Overview
This technique involves the abuse of legitimate Microsoft Power BI infrastructure to host phishing lures. By utilizing trusted `app.powerbi.com` domains, attackers bypass email security filters and gain user trust. The ultimate goal is the delivery of multiple rogue Remote Monitoring and Management (RMM) clients to establish persistent, redundant remote access to a target endpoint.
## Technical Details
- **Type**: Technique (Living-off-the-Cloud Phishing) and Malware (Rogue RMM)
- **Platform**: Windows
- **Capabilities**: Credential harvesting, remote desktop control, file transfer, and persistence.
- **First Seen**: September 10, 2024 (as reported by Huntress)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link
- **TA0002 - Execution**
- T1204.002 - User Execution: Malicious File
- **TA0003 - Persistence**
- T1219 - Remote Access Software
- T1053.005 - Scheduled Task/Job: Scheduled Task
- **TA0005 - Defense Evasion**
- T1564 - Hide Artifacts (Hidden download links)
- T1211 - Exploitation for Defense Evasion (Defense evasion tools)
- T1553.002 - Subvert Trust Controls: Code Signing (Abusing legitimate Power BI domains)
## Functionality
### Core Capabilities
- **Legitimate Domain Abuse**: Redirects victims to a fake reference document hosted on `hxxps[://]app.powerbi[.]com`.
- **Victim Fingerprinting**: Attacker-controlled landing pages analyze the victim's environment before serving the payload.
- **Programmatic Downloads**: Scripts on the landing page hide the download link and programmatically trigger it after a delay to evade automated sandboxes.
- **Redundant Persistence**: The campaign installs at least two distinct ScreenConnect instances with different configurations to ensure access remains if one is detected.
### Advanced Features
- **Defense Evasion Tooling**: Post-infection deployment of specialized tools designed to disable security software.
- **Delayed Execution**: The use of scheduled tasks to trigger malicious activity at a later time, complicating incident response timelines.
## Indicators of Compromise
- **File Names**: `ScreenConnect.ClientSetup.msi` (often renamed or bundled)
- **Network Indicators (Defanged)**:
- `hxxps[://]app.powerbi[.]com/view?r=eyJrIjoiNTk0NmViNDktYzM1Yy00MjEwLTkyZTctNGU5ZTJmYzMzYjEwIiwidCI6IjU1YTI4YmU2LTFiYzQtNDIzMS05MTA0LTdkMmFlYTVmMGZhNiJ9`
- Attacker-controlled redirectors: [Specific C2/download domains omitted from snippet, but generally involve look-alike or low-reputation URLs].
- **Behavioral Indicators**:
- `msiexec.exe` launching from unusual paths or triggered by browser processes.
- Multiple instances of `ScreenConnect.Client.exe` running from different `AppData` or `ProgramData` directories.
- Creation of new Scheduled Tasks immediately following a file download from a browser.
## Associated Threat Actors
- **Unknown**: While specific group naming (e.g., APT#) was not provided in the source, the TTPs align with financially motivated actors or Initial Access Brokers (IABs).
## Detection Methods
- **Signature-based detection**: Flagging unauthorized ScreenConnect installers by checking for specific `OrganizationName` strings in the MSI properties.
- **Behavioral detection**: Monitoring for "living-off-the-cloud" patterns where `app.powerbi.com` is the referrer for an external file download.
- **Process Monitoring**: Alerting on multiple RMM clients installed on a single endpoint, especially when not managed by the organization's standard IT policy.
## Mitigation Strategies
- **Prevention measures**: Implement strict "Allow-listing" for RMM tools; block unauthorized RMM traffic at the network level.
- **Hardening recommendations**:
- Restrict the ability of standard users to run `msiexec.exe` or install software in profile directories.
- Configure email gateways to inspect links within the Power BI domain for suspicious redirect patterns.
## Related Tools/Techniques
- **AnyDesk / Atera / NetSupport**: Similar RMM tools frequently abused by threat actors.
- **Living-off-the-Cloud (LotC)**: Using legitimate SaaS platforms (like Google Drive, Dropbox, or Power BI) for hosting malware.