CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access

CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access
CSuite is a multi-stage phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and delivery of legitimate management tools to compromise both identities and endpoints. The campaign heavily targets US organizations and uses trusted brands like Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365, with shared infrastructure linking the phishing and remote-access arms. #CSuite #ScreenConnect #Microsoft365 #Adobe #DocuSign #Cloudflare #GitHub

Keypoints

  • CSuite blends phishing, session theft, and remote-access delivery in one operation.
  • The campaign uses trusted business themes such as Adobe, DocuSign, Zoom, SharePoint, and Microsoft 365 to lure victims.
  • The operation targets organizations in the US and Europe, with 60% of identified victim organizations based in the United States.
  • ANY.RUN identified 351 related sandbox analyses across 170 hosts, showing broad activity and reuse of infrastructure.
  • The panel data included 216 unique Chameleon victims, 29 captured Microsoft 365 sessions, 1,593 lure documents, and 15,955 harvested email addresses.
  • CSuite delivers legitimate remote-management and endpoint-management tools such as ScreenConnect, Action1, Atera, Syncro, and PDQ Connect as RAT-like payloads.
  • The same infrastructure, domains, operator accounts, and exfiltration channels connect the phishing and remote-access components of the campaign.

MITRE Techniques

  • [T1583.001 ] Acquire infrastructure: domains – CSuite registered and used many lure, redirector, and harvester domains, including lookalike names to impersonate real organizations. [‘used one registrar account with WHOIS privacy to register 38 lure, redirector and harvester domains’]
  • [T1583.004 ] Acquire infrastructure: server – The campaign used shared hosting to host lure pages and payload archives. [‘used the shared-hosting account to host lure pages and payload archives’]
  • [T1585.003 ] Establish accounts: cloud accounts – CSuite used Cloudflare accounts and API keys to front and automate its domains. [‘used two Cloudflare accounts with connected API keys to front and automate its domains’]
  • [T1608.001 ] Stage capabilities: upload malware – Payloads were staged through archives on shared hosting and installers on public code-hosting. [‘used archives on its shared-hosting account and installers committed to a public code-hosting account to deliver payloads’]
  • [T1566.002 ] Phishing: spearphishing link – The Adobe Sender module sent share invitations from hijacked Adobe Document Cloud tenants. [‘dispatched 1,593 share invitations from hijacked Adobe Document Cloud tenants’]
  • [T1189 ] Drive-by compromise – The lure page started the archive download automatically on page load through a synthetic click. [‘start the archive download on page load’]
  • [T1204.002 ] User execution: malicious file – Victims were instructed to extract and run downloaded archives or installers. [‘have the victim extract and run the archived executable’]
  • [T1036.005 ] Masquerading: match legitimate name – The malware and installers were renamed to resemble benign Adobe or business files. [‘used the renamed Adobe binary SSAStatement.exe to present the loader as a financial statement’]
  • [T1574.001 ] Hijack execution flow: DLL side-loading – The renamed loader used a substituted DLL in its directory to run attacker code. [‘used a substituted msvcp140.dll in its own directory to execute attacker code’]
  • [T1553.002 ] Subvert trust controls: code signing – A valid Adobe DigiCert signature was used to pass reputation checks. [‘used a valid Adobe DigiCert signature on the loader to pass signature and reputation checks’]
  • [T1059.003 ] Command and scripting interpreter: Windows command shell – Batch droppers checked admin rights and launched silent installation commands. [‘test for administrative rights with fltmc or net session and then install the agent silently’]
  • [T1059.001 ] Command and scripting interpreter: PowerShell – PowerShell was used to self-elevate and download payloads. [‘used Start-Process -Verb RunAs to self-elevate and Net.WebClient.DownloadFile to fetch the agent package’]
  • [T1105 ] Ingress tool transfer – Agent packages were pulled from vendor cloud and public code-hosting URLs. [‘pulled agent packages from the vendor’s own cloud and from raw URLs on a public code-hosting account’]
  • [T1218.007 ] System binary proxy execution: msiexec – The newer batch dropper used msiexec with a remote HTTPS URL to install ScreenConnect. [‘handed msiexec /i an HTTPS URL with /quiet /norestart’]
  • [T1219 ] Remote access software – ScreenConnect was used as a remote-management client to control hosts. [‘used a ScreenConnect client bound to instance-t7o41i-relay[.]screenconnect[.]com to take control of the host’]
  • [T1547.002 ] Boot or logon autostart: authentication package – ScreenConnect appended an authentication package to LSA to load at boot. [‘used ScreenConnect.WindowsAuthenticationPackage.dll appended to LSA to load at boot’]
  • [T1556 ] Modify authentication process – A registered credential provider was used to capture interactive logon. [‘used a registered credential provider CLSID to capture interactive logon’]
  • [T1539 ] Steal web session cookie – Per-domain cookie capture modes were used to take over authenticated Office 365 sessions. [‘used per-domain cookie capture modes to take over authenticated Office 365 sessions’]
  • [T1621 ] Multi-factor authentication request generation – Device-code pages drove victims through attacker-initiated Microsoft approval flows. [‘used device-code landing pages on maillive[.]sbs to drive victims through an attacker-initiated approval’]
  • [T1567 ] Exfiltration over web service – Visitor data was reported through a messaging bot API from browser and server-side code. [‘used a messaging bot API to report each visitor’]
  • [T1114.002 ] Remote email collection – Operators used a remote-desktop foothold to work inside captured mailboxes manually. [‘used the remote-desktop host 207.189.19[.]40:26688 to work inside captured mailboxes by hand’]
  • [T1090.003 ] Multi-hop proxy – Cloudflare Workers reverse proxies were used to hide the origin of lure domains. [‘used Cloudflare workers.dev reverse proxies to hide the origin of its lure domains’]
  • [T1497 ] Virtualization and sandbox evasion – The kit used blacklist checks, honeypot fields, fingerprinting, and delayed resource exhaustion to stall analysis. [‘honeypot fields, automation checks … and a resource-exhaustion loop armed on a 30-to-120-second timer’]
  • [T1480 ] Execution guardrails – Address blocklists, geo filters, and fingerprint bans restricted who could see the phishing page. [‘address blocklists, two /24 ranges, a fingerprint ban list and a six-country geographic filter’]
  • [T1056.003 ] Input capture: web portal capture – The Chameleon page captured passwords twice before redirecting victims onward. [‘used providers/chameleon.php to take the password twice’]
  • [T1656 ] Impersonation – The credential page used logos and a live website screenshot to mimic the target company portal. [‘used logos and a live website screenshot pulled from public branding services’]

Indicators of Compromise

  • [URI path ] Shared kit path and sandbox pivot point – /m/js/utils.js, /e-sign.php
  • [Domain ] Lure, redirect, and panel infrastructure – gddfzxa[.]online, maillive[.]sbs, corporate-sync-gate[.]net
  • [Domain ] Lookalike impersonation domains – ambitiousaboutautismorguk[.]com, solarengyloanfunds[.]com
  • [IP address and port ] Remote access and staging infrastructure – 207.189.19[.]40:26688, 64.204.180[.]203:8040
  • [IP address ] Sending relays and panels – 188.127.227[.]18, 141.133.174[.]208
  • [File name ] Payload archives and installers – AdobePdf_Reader.zip, ScreenConnect.ClientSetup.msi
  • [File name ] Dropper scripts and staged installers – NMLS 2026 Updated Agreement.bat, Amended_Agreement02026.vbs
  • [File hash ] Notable analyzed samples – ae7af8159f06a059411411e5e816b415e32213371fb085ced1dc5679a0112c48, c0eb04dcfa745653c466c34978a1f3b4e5041f526be8c2e46b8c722498ca746a
  • [Cloud storage bucket ] Payload and lure hosting – btconnect-com, docsend-765676
  • [Code-hosting account ] Staging account for installers – github[.]com/Ivan3900


Read more: https://any.run/cybersecurity-blog/csuite-attack-analysis/