HackerFeeds

CyberSecurity News

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

The Hacker News
· September 30, 2026

AI summary

Researchers at ANY.RUN have been tracking a phishing campaign targeting US organizations, with a significant portion of the activity coming from the United States. The campaign, known as CSuite, has been observed in 351 sandbox analyses, with certain sectors such as technology, manufacturing, government, and consulting being particularly affected. The attackers are using a combination of techniques, including stealing Microsoft 365 sessions and deploying remote-access tools, to gain broader access to compromised accounts. This allows the attackers to potentially carry out further malicious activities, including fraud. The campaign's focus on stealing sessions and deploying remote-access tools enables the attackers to escalate a phishing incident into a more extensive compromise.

Countries in focus

Read the full article at The Hacker Newsthehackernews.com/2026/09/us-focused-csuite-phishing-steals.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.