Full Report
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
Analysis Summary
# Tool/Technique: CSuite Phishing Campaign
## Overview
CSuite is a sophisticated, US-centric phishing operation designed to achieve dual-path compromise. It combines traditional identity theft (Microsoft 365 session hijacking) with the deployment of legitimate Remote Monitoring and Management (RMM) tools to gain persistent endpoint access. The campaign primarily targets high-value sectors such as technology, manufacturing, and government.
## Technical Details
- **Type:** Phishing Campaign / Access Facilitator
- **Platform:** Windows (Endpoint), Microsoft 365 (Cloud/SaaS)
- **Capabilities:** Credential harvesting, Session token theft (AiTM), Device-code phishing, Privilege escalation, RMM deployment.
- **First Seen:** Reported September 2026 (via ANY.RUN)
## MITRE ATT&CK Mapping
- **TA0001 - Initial Access**
- T1566.002 - Phishing: Spearphishing Link
- **TA0002 - Execution**
- T1059.003 - Command and Scripting Interpreter: Windows Command Shell (BAT)
- T1059.005 - Command and Scripting Interpreter: VisualBasic (VBS)
- **TA0003 - Persistence**
- T1219 - Remote Access Software
- **TA0004 - Privilege Escalation**
- T1068 - Exploitation for Privilege Escalation
- **TA0006 - Credential Access**
- T1557 - Adversary-in-the-Middle (Session Theft)
- T1528 - Steal Application Access Token
## Functionality
### Core Capabilities
- **Multi-Brand Lures:** Impersonates trusted business services including Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365.
- **Identity Compromise:** Utilizes device-code phishing and session theft to bypass Multi-Factor Authentication (MFA) and take over Microsoft 365 accounts.
- **Payload Delivery:** Delivers installers, archives, or lightweight scripts (BAT/VBS) via phishing pages to initiate endpoint infection.
### Advanced Features
- **Dual-Path Attack:** Simultaneously targets the user's cloud identity and their physical workstation to ensure redundancy if credentials are changed.
- **RMM Abuse:** Leverages legitimate tools like **ScreenConnect** and **Action1** to maintain persistent access, which often evades traditional antivirus detection due to the software's legitimate nature.
- **Privilege Elevation:** Included scripts are capable of elevating privileges on the target endpoint during the RMM installation process.
## Indicators of Compromise
- **File Names:** `utils.js` (Commonly found in `/m/js/` directory on phishing hosts)
- **Network Indicators:**
- `[domain]/m/js/utils.js` (Pattern for CSuite lure infrastructure)
- **Behavioral Indicators:**
- Execution of BAT or VBS files immediately following a browser-based PDF/Document preview.
- Unauthorized installation of ScreenConnect or Action1 RMM agents.
- Unexpected PowerShell execution originating from browser processes.
## Associated Threat Actors
- **Status:** Unknown/Unspecified (Activity shows a heavy concentration in the United States, accounting for 51% of observed telemetry).
## Detection Methods
- **Signature-based detection:** Monitoring for the specific JavaScript path `/m/js/utils.js` across web traffic.
- **Behavioral detection:**
- Detection of "Living off the Land" (LotL) scripts (BAT/VBS) spawned by web browsers.
- Monitoring for unauthorized RMM software installation in environments where ScreenConnect or Action1 are not standard.
- **Sandboxing:** Interactive analysis of Adobe/DocuSign lures to observe post-click redirects and payload drops.
## Mitigation Strategies
- **Identity Hardening:** Implement Phishing-Resistant MFA (FIDO2/WebAuthn) to prevent session theft and device-code phishing.
- **Software Restriction Policies:** Use Application Control (e.g., AppLocker or Windows Defender Application Control) to block unauthorized RMM tools.
- **Email Security:** Enhance link protection and sandboxing for incoming attachments masquerading as DocuSign or Adobe files.
- **Session Management:** Reduce session lifetimes for Microsoft 365 to limit the window of opportunity for stolen tokens.
## Related Tools/Techniques
- **Adversary-in-the-Middle (AiTM):** Similar to Evilginx2 tactics for session hijacking.
- **RMM Abuse:** Similar to tactics used by Ransomware affiliates to maintain persistence.
- **Device Code Phishing:** A technique increasingly used to bypass modern authentication prompts.