EXECUTIVE SUMMARY:
A phishing campaign abuses legitimate Microsoft Power BI infrastructure to distribute rogue ScreenConnect remote management clients. Threat actors use phishing emails containing links to publicly accessible Power BI pages that imitate reference documents and display a deceptive "Download Reference" prompt. Because the initial link uses a trusted Power BI domain, the campaign can appear legitimate and potentially bypass controls that trust commonly used cloud services. Clicking the prompt redirects victims to attacker-controlled infrastructure before initiating the download of unauthorized remote access software.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A phishing campaign abuses legitimate Microsoft Power BI infrastructure to distribute rogue ScreenConnect remote management clients. Threat actors use phishing emails containing links to publicly accessible Power BI pages that imitate reference documents and display a deceptive "Download Reference" prompt. Because the initial link uses a trusted Power BI domain, the campaign can appear legitimate and potentially bypass controls that trust commonly used cloud services. Clicking the prompt redirects victims to attacker-controlled infrastructure before initiating the download of unauthorized remote access software.[emaillocker id="1283"]
The attack begins with an Outlook phishing email that redirects the recipient to a fake reference document hosted through Power BI. After the victim selects the download prompt, a new browser tab opens an attacker-controlled webpage that performs extensive environment fingerprinting, including checks of the operating system, browser, user-agent, device type, screen size and automation indicators. The collected information can include the victim's IP address, geolocation and browsing details which are transmitted through a Telegram bot. The webpage uses delayed execution to trigger a hidden download link and deliver a malicious ScreenConnect installer. The installer establishes an initial rogue ScreenConnect client before deploying a second client connected to separate attacker-controlled infrastructure. In some cases, a CMD file launches a PowerShell script that downloads an additional installer, removes the initial ScreenConnect instance and establishes another remote access connection. The activity also includes a defense-evasion utility and a scheduled task configured to repeatedly execute the PowerShell script which provides redundant access and complicates remediation.
The campaign demonstrates how trusted cloud services can be abused to deliver remote access tooling while reducing suspicion during the initial phishing stage. Organizations should scrutinize links hosted on legitimate cloud platforms when they lead to unexpected downloads or document verification prompts. Monitoring for unauthorized ScreenConnect installations, unfamiliar ScreenConnect connections, PowerShell activity, suspicious scheduled tasks and endpoints containing multiple remote management clients can help identify this activity. Remote management software should also be restricted to approved instances and unexpected installations should be investigated promptly.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1053.005 | Scheduled Task/Job | Scheduled Task |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
| Discovery | T1082 | System Information Discovery | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
REFERENCES:
The following reports contain further technical details:
https://www.huntress.com/blog/screenconnect-power-bi