A phishing operation targeting senior business leaders has reached 351 sandbox analyses, with more than half of all submissions originating in the United States, according to research published by ANY.RUN. The campaign, dubbed CSuite, combines credential theft with remote-access tool installation to compromise both Microsoft 365 accounts and employee endpoints. By attacking identity and device layers simultaneously, the operation can escalate a single phishing incident into sustained network access, financial fraud, and internal account takeover.

The ANY.RUN research shows that 51% of CSuite-related sandbox submissions came from the United States, while India accounted for 18% of activity. Additional detections appeared across the Philippines, Australia, the United Kingdom, and Canada. Technology, manufacturing, government and administration, and consulting sectors showed the highest exposure levels within the dataset. The attack chain begins with forged business communications impersonating Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, then branches into two paths: one delivers installers, archives, or BAT and VBS droppers that install legitimate management tools like ScreenConnect or Action1 for remote endpoint control, while the other pushes victims into credential-harvesting or device-code phishing flows designed to capture active Microsoft 365 sessions.

In one sandbox session analyzed by the researchers, an Adobe-themed lure delivered a BAT file that elevated system privileges and installed ScreenConnect, demonstrating how rapidly a phishing page can transition into full remote endpoint access. The report notes that CSuite can provide attackers with control over both business accounts and employee devices, expanding potential impact from mailbox compromise to persistent presence inside corporate environments. Because the operation targets both identity and endpoint simultaneously, security teams may need to contain stolen sessions and compromised systems at the same time, increasing response effort and business disruption.

The report outlines several potential outcomes from successful CSuite compromises: mailbox takeover allows attackers to monitor payment threads and impersonate trusted employees, while access to genuine business correspondence can enable invoice manipulation, payment redirection, and supplier fraud. Abused remote management tools can maintain attacker connectivity to victim systems long after the initial phishing event, and compromised accounts can be weaponized to target colleagues, partners, or customers from a trusted identity. The researchers recommend that security leaders focus on shortening investigation time, controlling unauthorized remote-access tooling, and improving visibility across both identity and endpoint activity, noting that CSuite infrastructure can rotate quickly and manually maintained blocklists can become outdated fast. Organizations using ANY.RUN's solutions have reported 94% faster threat triage, 20% less Tier 1 investigation time, 30% fewer escalations to senior analysts, and 21 minutes lower mean time to respond per incident.

The report emphasizes that analysts need full attack-chain visibility to reconstruct the sequence from business lure through browser activity, script execution, payload delivery, and remote-access installation, rather than judging an incident from a single file or domain. Organizations should feed current malicious infrastructure into existing security controls and use structured investigation reports to reduce preparation work at the handoff stage, the researchers conclude. CSuite's dual-layer approach leaves little room for siloed response, requiring coordination across identity and endpoint security functions to prevent a single phishing email from becoming a months-long business compromise. The convergence of credential theft and remote access tooling in a single campaign reflects a strategic shift that may force many organizations to rethink how they staff and structure incident response teams. Defenders accustomed to treating phishing as an email problem now face adversaries who view each successful lure as the opening move in a broader takeover operation.