CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys ScreenConnect/Action1 RMM Tools Against US and EU Organizations

CSuite Phishing Operation Steals Microsoft 365 Sessions via (TL-2026-2802), also tracked as CSuite, is a high-severity phishing campaign, first published 2026-09-30. It has no confirmed attribution, affects Microsoft Microsoft 365 / Entra ID (OAuth device-code flow, user, maps to 18 MITRE ATT&CK techniques (T1056.003, T1059.001, T1059.003), and is covered by 9 detection rules and 31 indicators of compromise.

Key facts for TL-2026-2802

Threat ID
TL-2026-2802
Also known as
CSuite, CSuite v1.1
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-30
Last reviewed
2026-09-30
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
technology, manufacturing, government administration, consulting, education, finance
Target regions
North America, Europe, india, philippines, australia, united kingdom, canada
Detection rules
9
Indicators of compromise
31

Malware and tooling in CSuite Phishing Operation Steals Microsoft 365 Sessions via

Malware and tooling: Action1, Atera, PDQ Connect, ScreenConnect, Syncro

ANY.RUN documented CSuite, a phishing-and-remote-access operation using Adobe, DocuSign, Zoom, Google Meet, Dropbox and Microsoft 365 lures that either steals Microsoft 365 credentials/sessions (including device-code OAuth phishing) or drops BAT/VBS/MSI installers for legitimate RMM agents (ScreenConnect, Action1, Atera, Syncro, PDQ Connect). 351 sandbox analyses across 170 hosts; 51% of submissions from the US, 18% from India.

How CSuite Phishing Operation Steals Microsoft 365 Sessions via works

CSuite is a multi-path phishing operation reported by ANY.RUN (22 Sep 2026) and covered by The Hacker News on 30 Sep 2026. Victims receive document-themed lures (Adobe Document Cloud share invitations from hijacked Adobe tenants, DocuSign envelopes, Zoom/Google Meet invites, Dropbox documents, Microsoft 365 voicemail, SharePoint, Teams, WeTransfer, DocSend), delivered either through hijacked Adobe tenants or dedicated SMTP relays (PowerMTA on port 2525, DKIM published). Landing pages sit on operator domains and on compromised legitimate websites (e.g. an Australian escrow site) behind a shared anti-analysis gate, /m/js/utils.js (66 KB, header 'Enhanced CAPTCHA Protection Utilities'), reused across 170 hosts over roughly seven months. The gate filters on user-agent (crawler/automation and security-vendor signatures), IP blocklists and geolocation, browser fingerprinting, reCAPTCHA v3 score and human-interaction telemetry, and adds honeypot fields, suppressed dev-tools shortcuts and a resource-exhaustion trap.

Path 1 (endpoint): a counterfeit Adobe Reader/DocuSign viewer auto-triggers a synthetic download click and serves an archive (e.g. AdobePdf_Reader.zip containing ScreenConnect.ClientSetup.msi), a direct MSI, or a BAT/VBS dropper. The 324-byte batch dropper tests for admin rights, self-elevates through PowerShell Start-Process -Verb RunAs, and runs msiexec /i against a raw GitHub URL with /quiet /norestart. Other droppers write the installer to a temp directory and show a fake 'Application Error' popup. Installed agents register to operator-controlled tenants: ScreenConnect with a hardcoded relay, a credential-provider CLSID and an LSA authentication package (ScreenConnect.WindowsAuthenticationPackage.dll) that loads at boot and survives safe mode with networking; Action1, Atera, Syncro and PDQ Connect agents are staged under Adobe/Dotloop/Zoom names. One observed loader used a signed Adobe binary (SSAStatement.exe) that side-loads a substituted msvcp140.dll.

Path 2 (identity): traffic is routed by email provider. Microsoft accounts go to device-code OAuth pages (Next.js frontend calling /api/lure/config, /api/initiate and /api/status; the victim is sent to the real Microsoft device-login page and the operator receives access and refresh tokens without capturing a password), Google accounts go to a separate capture flow, and others go to a 'Chameleon' credential harvester (providers/chameleon.php) that impersonates the victim's organization with logos and screenshots. The 'CSuite v1.1' admin panel (host maillive.sbs) has Sessions, Adobe Sender, Offline File Generator, DocForge, Auto Redirect and Worker Links modules; Cloudflare workers.dev reverse proxies hide origin domains and a Telegram bot API reports each visitor. The panel showed 29 captured Microsoft 365 sessions, 1,593 documents sent through hijacked Adobe tenants, and 15,955 harvested email addresses; 216 unique Chameleon victims were seen. Captured mailboxes were worked by hand over a remote-desktop host, creating invoice-fraud and payment-redirection risk. ANY.RUN reports the operator accidentally sent hosting-panel and remote-desktop credentials to the same recipient on 7 Aug 2026, tying delivery and capture infrastructure together. No named threat actor is attributed in the sources. Targeted sectors: technology, manufacturing, government/administration, consulting, education and mortgage licensees.

MITRE ATT&CK techniques used in TL-2026-2802

Credential Access

T1056.003 Input Capture: Web Portal Capture; T1539 Steal Web Session Cookie; T1556 Modify Authentication Process; T1621 Multi-Factor Authentication Request Generation

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Command and Control

T1090.003 Proxy: Multi-hop Proxy; T1219 Remote Access Tools

Collection

T1114.002 Email Collection: Remote Email Collection

Defense Evasion

T1218.007 System Binary Proxy Execution: Msiexec; T1497 Virtualization/Sandbox Evasion; T1574.001 DLL

Persistence

T1547.002 Boot or Logon Autostart Execution: Authentication Package

defense-impairment

T1553.002 Subvert Trust Controls: Code Signing

Initial Access

T1566.002 Phishing: Spearphishing Link

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Acquire Infrastructure: Domains

Affected products and versions in CSuite Phishing Operation Steals Microsoft 365 Sessions via

  • Microsoft — Microsoft 365 / Entra ID (OAuth device-code flow, user sessions)
    Vulnerable versions: Tenants permitting device-code authentication
  • ConnectWise — ScreenConnect (abused legitimate client)
  • Action1 — Action1 RMM agent (abused legitimate client)
  • Microsoft — Windows endpoints (msiexec, PowerShell, LSA authentication packages)

Remediation for CSuite Phishing Operation Steals Microsoft 365 Sessions via

Immediate actions

  • Hunt proxy/DNS/EDR telemetry for requests to the path /m/js/utils.js and block the listed CSuite domains and IPs
  • Revoke refresh tokens and active sessions for any user who entered a device code or visited a suspected lure page; review Entra sign-in logs for the device-code authentication flow
  • Inventory and remove unsanctioned ScreenConnect, Action1, Atera, Syncro and PDQ Connect agents, especially those registering to relays or tenants you do not own (e.g. instance-t7o41i-relay.screenconnect.com)
  • Search mailboxes for Adobe/DocuSign share invitations and quarantine matching messages

Workarounds

  • Restrict outbound access to RMM vendor cloud endpoints to the tenants your organization uses
  • Block execution of .bat/.vbs files delivered in archives from email or browser downloads

Longer-term hardening

  • Block the OAuth device-code flow with Conditional Access for users who do not need it
  • Application-allowlist RMM software (WDAC/AppLocker) and alert on msiexec installing from remote HTTPS or raw GitHub URLs
  • Alert on new LSA authentication packages and credential-provider CLSID registrations
  • Train users to distrust prompts to copy a verification code into a Microsoft sign-in page

Timeline of CSuite Phishing Operation Steals Microsoft 365 Sessions via

  • Earliest sample of the shared /m/js/utils.js anti-analysis gate observed in ANY.RUN sandbox corpus
  • Earliest public submission of the PHP kit build; CSuite panel domain-registry additions begin (lure hosts added 2 Apr through 14 Aug)
  • Complete gate-plus-Chameleon credential capture deployment observed on compromised site escrowadmin.com.au under /upload/cgi/
  • Four TLS certificates issued on shared hosting (greenbullet.ba) for gddfzxa.online, ghs.coorpes.com, greaterheights.sbs and mmswerod.sbs
  • Operator sent hosting-panel and remote-desktop (207.189.19.40:26688) credentials to the same recipient, linking delivery and capture infrastructure
  • ScreenConnect.ClientSetup.msi uploaded to GitHub repositories mobi and jppp under account Ivan3900
  • Further ScreenConnect.ClientSetup.msi uploaded to the Ivan3900/test repository
  • Final kit path observed in sandbox telemetry
  • ANY.RUN published its CSuite attack analysis (351 sandbox analyses across 170 hosts)
  • The Hacker News reported the US-focused CSuite campaign

Sources cited for CSuite Phishing Operation Steals Microsoft 365 Sessions via

More in phishing

Detection coverage for TL-2026-2802

As of 2026-09-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2802 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats