CSuite Phish Steals M365 Sessions, Installs RMM

The Hacker News · Medium sophistication
Last updated October 1, 2026

Researchers observed a real phishing campaign (“CSuite”) heavily targeting U.S. organizations using familiar business-themed lures (DocuSign, Adobe, Zoom/Meet, Dropbox, Microsoft 365). After a victim engages, the attackers either steal Microsoft 365 sessions (enabling mailbox takeover and fraud) or trick users into running droppers that install legitimate remote-management tools for persistent access to employee devices.

How the Attack Worked

The CSuite campaign relies on business lures that employees see every day: a DocuSign envelope needing a signature, an Adobe document shared for review, a Microsoft 365 access notice. These themes were used across hundreds of sandbox analyses, with over half of submissions originating from the United States. Instead of relying on a single tactic, the campaign splits into two distinct outcomes once a victim engages.

The first path targets identity directly. Victims are pushed into credential-harvesting pages or device-code phishing flows designed to capture Microsoft 365 access and active sessions, which can allow mailbox takeover and downstream fraud without the attacker ever needing a traditional password. The second path targets the device itself. Instead of a normal PDF, the victim receives installers, archives, or lightweight BAT/VBS droppers. In one documented sandbox session, an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect, a legitimate remote management tool repurposed for attacker access.

Why It Succeeded

The lures work because they mimic routine business processes that employees are conditioned to act on quickly: signing documents, joining a meeting, or confirming account access. A forged DocuSign envelope sent under the name of a law firm adds authority and urgency, reducing the likelihood that a recipient pauses to verify. The use of legitimate software names like Adobe, Zoom, and Microsoft 365 also means the lures look identical to normal daily correspondence, making them harder to flag on sight.

What to Watch For

  • Unexpected DocuSign, Adobe, or Microsoft 365 emails with no prior context
  • Links that lead to sign-in or session approval screens instead of the expected document viewer
  • Attachments that are archives, installers, or script files (BAT/VBS) rather than standard documents
  • Device-code or session approval prompts triggered from an email link rather than a normal login
  • Unexpected installation of remote management software like ScreenConnect or Action1

Building Resistance

Organizations in technology, manufacturing, government, and consulting sectors were noted as most exposed, and roles like C-Suite, executive assistants, finance, legal, and IT service desk staff are prime targets. Employees should be trained to verify document, meeting, and access requests through a separate, known channel rather than clicking embedded links. Running scripts to

Key findings

  • Campaign observed across “351 sandbox analyses,” with “51% of submissions coming from the United States.”
  • Uses common business service themes: “Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365.”
  • Two main outcomes: (1) steal Microsoft 365 access/sessions via credential-harvesting or device-code flows, and/or (2) install legitimate RMM tools (e.g., ScreenConnect, Action1) for remote control of endpoints.
  • Example observed: “an Adobe-themed lure delivered a BAT file that elevated privileges and installed ScreenConnect.”
  • Most exposed sectors noted: “Technology, manufacturing, government and administration, and consulting.”

Who’s being targeted

  • Commonly targeted roles: C-Suite/Executives, Executive Assistants, Finance/AP, Legal, IT Service Desk, All employees in high-exposure sectors (technology, manufacturing, government, consulting).
  • Affected industries: Technology, Manufacturing, Government and administration, Consulting.
  • Attack channels: email.
  • Impersonated: DocuSign (and a law firm sender), Adobe (document/PDF-related workflow), Microsoft 365.

Red flags to watch for

  • Unexpected DocuSign request (no prior context)
  • Sender context relies on urgency/authority (law firm)
  • Link leads away from expected DocuSign/Microsoft sign-in and may prompt for credentials/session approval
  • Attachment is an archive/installer/script (BAT/VBS) instead of a normal PDF
  • Request to run a script to view a document
  • Legitimate remote management software gets installed after opening the file
  • Sign-in flow is initiated from an unsolicited email link
  • Prompts for device-code style approval rather than normal login
  • The request is framed as urgent/account access related
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the CSuite phishing campaign?

CSuite is a phishing campaign heavily targeting U.S. organizations that uses familiar business lures like DocuSign, Adobe, Zoom, Google Meet, Dropbox, and Microsoft 365 to trick victims into clicking links or opening files.

What happens if a victim falls for a CSuite lure?

Victims are either pushed into credential-harvesting or device-code phishing flows that capture Microsoft 365 access and active sessions, or tricked into running droppers that install legitimate remote management tools such as ScreenConnect or Action1.

Which industries are most exposed to CSuite phishing?

Technology, manufacturing, government and administration, and consulting were noted as the most exposed sectors.

Why is RMM tool installation dangerous in this attack?

Because the installed software is legitimate remote management software, it can give attackers persistent remote access to an employee's endpoint without triggering typical malware alerts.

Read the video transcript

You get an email: “DocuSign, Please review and sign the attached envelope,” supposedly from a law firm. Looks routine, right? Behind that click is CSuite: it either steals your Microsoft 365 session with a fake sign-in, or installs remote-control tools like ScreenConnect or Action1 onto your laptop. Here’s the tell: the “Adobe Document Shared” email doesn’t give you a PDF. It gives you a BAT or VBS file and says, “run this to view the document.” That’s how ScreenConnect got silently installed in real cases. If any DocuSign, Adobe, or M365 email wants you to run a script or installer to see a document, stop. Don’t open it, forward it to the security team and ask them to check it.

Similar attacks

Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
N0va Phishkit Uses Trusted Apps to Steal SSO Access

N0va Phishkit Uses Trusted Apps to Steal SSO Access

A phishing kit dubbed N0va is targeting organizations in North America and Europe by impersonating familiar business services (like Microsoft Teams/SharePoint and DocuSign) and pushing victims through legitimate sign-in flows. By capturing authentication tokens rather than dropping obvious malware,…

September 16, 2026
Fake DocuSign Flow Tricks Users Into RMM Installs

Fake DocuSign Flow Tricks Users Into RMM Installs

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep…

July 20, 2026
Malicious Calendar Invites Surge With Malware Links

Malicious Calendar Invites Surge With Malware Links

Attackers are sending fake calendar meeting invites that can be automatically added to a victim’s calendar, even if the email is blocked. A documented example used a Google Calendar invite with a financial “invoice credit” lure to drive victims to a hosted webpage and download a malicious…

September 18, 2026