Skip to main content

Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs

0
Medium
Published: 10/07/2026 (10/07/2026, 16:55:07 UTC)
Source: AlienVault OTX General

Description

A phishing campaign exploited legitimate Microsoft Power BI domains to distribute rogue ScreenConnect remote monitoring tools. Attackers sent phishing emails with links redirecting victims to fake reference documents hosted on Power BI infrastructure. Clicking the download link led to attacker-controlled sites that fingerprinted victims' systems before downloading malicious ScreenConnect installers. Multiple ScreenConnect instances were deployed for persistent remote access, with scheduled tasks created to maintain persistence. The campaign used browser fingerprinting and Telegram bots to filter victims and track infections, leveraging trusted Microsoft domains to bypass email security and increase credibility.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 08:18:41 UTC

Technical Analysis

In September, attackers conducted a phishing campaign abusing Microsoft Power BI domains to host fake reference documents. Victims received emails with embedded links that redirected to these Power BI-hosted pages. When victims clicked 'Download Reference,' they were redirected to attacker-controlled websites that fingerprinted their systems and browsers. This process triggered downloads of malicious ScreenConnect remote monitoring tool installers. The attackers deployed multiple ScreenConnect instances to maintain persistent remote access, including a second client connected to attacker infrastructure. Post-deployment, defense evasion tools were executed and scheduled tasks were created to run persistence scripts every two minutes. The campaign also employed browser fingerprinting and Telegram bots to filter victims and track infections, exploiting trusted Microsoft domains to evade email security controls and enhance attack credibility.

Potential Impact

The campaign enables attackers to gain persistent remote access to victim systems by deploying rogue ScreenConnect remote monitoring tools. This access allows execution of defense evasion techniques and continuous persistence via scheduled tasks. The abuse of trusted Microsoft Power BI domains increases the likelihood of successful phishing by bypassing email security controls and enhancing credibility. Victims are at risk of unauthorized remote control and potential further compromise.

Defensive Guidance

No official patch or fix is applicable as this is a phishing campaign abusing legitimate cloud infrastructure. Organizations should educate users about phishing risks, especially regarding unexpected emails with links to download documents. Email security solutions should be tuned to detect and block phishing attempts, even those leveraging trusted domains. Monitoring for unusual ScreenConnect installations and scheduled tasks may help detect compromise. Since the campaign abuses Microsoft Power BI domains, vigilance in verifying URLs and sources before downloading is critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/screenconnect-power-bi"]
Pulse Id
6ac6796b14fb153d2a5f5a04

Indicators of Compromise

Hash

ValueDescriptionCopy
hashf048400c23add8c75abe189393d33c873c02c74eeaf43d47b950c8d643763b35
—

Url

ValueDescriptionCopy
urlhttp://burnsworth.site/S/main.html
—
urlhttp://check.vykyn.click/E/
—
urlhttp://dailylifeproject.site/S/
—
urlhttp://essaywritingservice.site/S/main.html
—
urlhttp://onthegotree.site/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest
—
urlhttp://openpediatrics.site/S/main.html
—

Domain

ValueDescriptionCopy
domainburnsworth.site
—
domaindailylifeproject.site
—
domainessaywritingservice.site
—
domainonthegotree.site
—
domainopenpediatrics.site
—
domaincheck.vykyn.click
—

Threat ID: 6ac74e5f2cdf04f656fcc1ce

Added to database: 10/08/2026, 08:03:43 UTC

Last enriched: 10/08/2026, 08:18:41 UTC

Last updated: 10/08/2026, 18:48:07 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses