# Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue ScreenConnect RMMs

> Huntress observed phishing emails linking to fake reference documents on public Microsoft Power BI pages. A 'Download Reference' button opens attacker-controlled sites that fingerprint the host and then auto-download a rogue ScreenConnect client; a second ScreenConnect instance, a defense-evasion tool (HideUL_x64.exe) and a 2-minute scheduled task provide redundant persistence.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2998
- **ID:** TL-2026-2998
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Huntress SOC analysts observed a phishing campaign starting around 2026-09-10 that abuses Microsoft Power BI to host its lure. Victims receive an email (delivered to Outlook) containing a link to a public Power BI report on the legitimate app.powerbi.com domain. The report presents a fake reference document with a 'Download Reference' button, so the lure inherits the reputation of a trusted Microsoft service and slips past controls that trust the domain.

Clicking the button opens a new browser tab on an attacker-controlled site (observed: dailylifeproject.site, burnsworth.site, essaywritingservice.site, openpediatrics.site, each serving /S/ or /S/main.html). JavaScript on the page fingerprints the visitor: operating system, browser and version, mobile vs desktop, user agent, screen size, iframe context, cloud-provider cookies, public IP, geolocation, ISP, approximate coordinates, device type, UTC timestamp and automation indicators. Only Windows desktop visitors on non-Microsoft/known ISPs proceed; failed checks are redirected to check.vykyn.click/E/. Visitor telemetry is reported to a hardcoded Telegram bot credential that was reused across campaign domains. After a delay the page automatically downloads ScreenConnect.ClientSetup.exe from an attacker-controlled ScreenConnect cloud instance (hamham27.screenconnect.com, with guest-access parameters t=ILEAYEASAN, PERFECTO or PAPASUPE).

The first rogue client (instance ID 2b302081e9e777d0, relay instance-g01s1n-relay.screenconnect.com) executes LyN03DvVjUKPrun.cmd, which installs a second ScreenConnect client (instance ID 43773b3da4ccb17b) pointing at onthegotree.site, downloaded as ScreenConnect.ClientSetup.msi. The actor then runs the defense-evasion tool HideUL_x64.exe, described by Huntress as designed to hide the attacker's activity from the user and security software, and creates the scheduled task SCAutoRepairEvery2Min, which runs SCAutoFix.ps1 every two minutes. Multiple RMM clients mean that if one is removed another remains. Huntress's retrospective hunt found 22 additional impacted endpoints beyond the initial handful. No threat actor, sector or region attribution is given and no CVE is involved. The second-instance SHA256 (f048400c...) also appears in separate Huntress browser-in-the-browser (BiTB) Adobe-lure incidents from August 2026, indicating shared tooling or operators across rogue-ScreenConnect campaigns.

## MITRE ATT&CK

- T1583.001 Domains
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1053.005 Scheduled Task
- T1480 Execution Guardrails
- T1497.001 System Checks
- T1564 Hide Artifacts
- T1219.002 Remote Desktop Software

## Sources

- [Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs](https://www.huntress.com/blog/screenconnect-power-bi)
- [Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence](https://www.huntress.com/blog/phishing-bitb-rmm-attacks)
- [Threat View from the Lens of Huntress Adversary Tactics: September 2026](https://www.huntress.com/threat-library/adversary-tactics/september-2026)
- [Bank of America impersonators weaponize ScreenConnect, then make it hard to remove](https://helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/)
- [Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025](https://socprime.com/active-threats/rogue-screenconnect-common-social-engineering-tactics/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2998
