Threat Advisory

Power BI Phishing Campaign Leverages Trusted Cloud Services and Deceptive Download Prompts

Threat: Phishing Campaign
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A phishing campaign abuses legitimate Microsoft Power BI infrastructure to distribute rogue ScreenConnect remote management clients. Threat actors use phishing emails containing links to publicly accessible Power BI pages that imitate reference documents and display a deceptive "Download Reference" prompt. Because the initial link uses a trusted Power BI domain, the campaign can appear legitimate and potentially bypass controls that trust commonly used cloud services. Clicking the prompt redirects victims to attacker-controlled infrastructure before initiating the download of unauthorized remote access software.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A phishing campaign abuses legitimate Microsoft Power BI infrastructure to distribute rogue ScreenConnect remote management clients. Threat actors use phishing emails containing links to publicly accessible Power BI pages that imitate reference documents and display a deceptive "Download Reference" prompt. Because the initial link uses a trusted Power BI domain, the campaign can appear legitimate and potentially bypass controls that trust commonly used cloud services. Clicking the prompt redirects victims to attacker-controlled infrastructure before initiating the download of unauthorized remote access software.[emaillocker id="1283"]

The attack begins with an Outlook phishing email that redirects the recipient to a fake reference document hosted through Power BI. After the victim selects the download prompt, a new browser tab opens an attacker-controlled webpage that performs extensive environment fingerprinting, including checks of the operating system, browser, user-agent, device type, screen size and automation indicators. The collected information can include the victim's IP address, geolocation and browsing details which are transmitted through a Telegram bot. The webpage uses delayed execution to trigger a hidden download link and deliver a malicious ScreenConnect installer. The installer establishes an initial rogue ScreenConnect client before deploying a second client connected to separate attacker-controlled infrastructure. In some cases, a CMD file launches a PowerShell script that downloads an additional installer, removes the initial ScreenConnect instance and establishes another remote access connection. The activity also includes a defense-evasion utility and a scheduled task configured to repeatedly execute the PowerShell script which provides redundant access and complicates remediation.

The campaign demonstrates how trusted cloud services can be abused to deliver remote access tooling while reducing suspicion during the initial phishing stage. Organizations should scrutinize links hosted on legitimate cloud platforms when they lead to unexpected downloads or document verification prompts. Monitoring for unauthorized ScreenConnect installations, unfamiliar ScreenConnect connections, PowerShell activity, suspicious scheduled tasks and endpoints containing multiple remote management clients can help identify this activity. Remote management software should also be restricted to approved instances and unexpected installations should be investigated promptly.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1204.002 User Execution Malicious File
Persistence T1053.005 Scheduled Task/Job Scheduled Task
Defence Evasion T1036.005 Masquerading Match Legitimate Resource Name or Location
Discovery T1082 System Information Discovery -
Command and control T1071.001 Application Layer Protocol Web Protocols

 

REFERENCES:

The following reports contain further technical details:
https://www.huntress.com/blog/screenconnect-power-bi

[/emaillocker]
crossmenu