Researchers at ANY.RUN documented a phishing operation called CSuite that has been active against US organizations, with 51% of its 351 sandbox submissions traced to the United States. The campaign uses business-themed lures impersonating Adobe, DocuSign, Zoom, and Microsoft 365 to target employees in technology, manufacturing, government, and consulting.
CSuite diverges after the initial lure. One path delivers installers, archives, or BAT/VBS droppers that install legitimate remote management tools such as ScreenConnect or Action1, giving attackers interactive access to the endpoint. The other path pushes victims into credential-harvesting pages or device-code phishing flows designed to capture Microsoft 365 access tokens and active sessions.
Because both identity and endpoint can be compromised, the impact extends beyond a typical phishing incident. Attackers may read mail, redirect payments, maintain persistent remote access, and use trusted accounts to target others. The researchers advise security teams to reconstruct the full attack chain, monitor for unauthorized remote-access tooling, and feed current indicators into existing security controls rather than relying on manual blocklists.