US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

A sophisticated phishing campaign targeting US-based C-suite executives has compromised Microsoft 365 sessions, granting attackers remote access to companies’ internal networks. The hack also involves deploying Remote Monitoring and Management (RMM) tools to facilitate further exploitation.

The scheme, which leverages identity exposure as a key entry point, preys on senior-level employees who often possess high levels of access within their organizations. Once phished, these executives unwittingly surrender their login credentials, allowing attackers to infiltrate corporate networks via Microsoft 365 sessions. The intruders then use stolen session cookies to bypass multi-factor authentication (MFA) and move laterally across domains.

The exploitation chain begins with the attacker using social engineering tactics to trick targeted executives into divulging sensitive information. This can be achieved through cleverly crafted emails or phone calls that simulate legitimate communications from trusted sources, such as Microsoft itself. When an unsuspecting executive falls for this ruse, they inadvertently provide their login credentials and session cookies to the phisher.

The attackers’ next step involves deploying RMM tools on compromised systems, which enable them to remotely manage, monitor, and control affected devices. This capability allows hackers to execute additional malicious actions, such as data exfiltration or further lateral movement within the network. By doing so, they create a foothold for persistent access, rendering detection and response efforts more challenging.

The campaign’s reliance on identity exposure highlights the vulnerability of organizations that fail to implement robust security measures around their C-suite personnel. This includes educating executives about phishing threats and ensuring they use unique, complex passwords combined with MFA, which can prevent session cookie hijacking even if a credential is compromised.

While this attack specifically targets US-based companies, its tactics are not isolated and may be applicable to organizations globally. As such, it serves as a stark reminder of the importance of prioritizing identity security and maintaining awareness among all employees, especially those in high-privilege positions.


Source: The Hacker News — 2026-09-30