Skip to content

Image: cdn.builder.io · rights & removal

Executive Summary

Threat actors utilized legitimate Microsoft Power BI domains to host phishing lures, embedding malicious links in real dashboards to bypass email security filters and increase believability. Clicking a link redirected users to attacker-controlled landing pages that performed extensive browser and environment fingerprinting of the victim's machine. These pages then exfiltrated detailed telemetry, including IP addresses, geolocation, operating system details, and download activity, to an attacker-controlled Telegram bot.
The subsequent action involved opening new tabs leading to additional attacker domains used for further data collection before initiating the download of malicious ScreenConnect remote monitoring and management (RMM) instances. The attack leveraged trusted domain trust to deliver malware, demonstrating a technique where legitimate cloud services become infrastructure for illicit activity. Attackers employed multi-stage delivery, using one compromised session to fingerprint victims and another to initiate the actual payload download, often employing techniques like delayed downloads and internal script execution to evade immediate detection.

Facts Only

* Phishing emails contained an embedded link to a legitimate Microsoft Power BI domain.
* Clicking the link redirected targets to a page on a legitimate Power BI domain.
* The landing page performed browser and environment fingerprinting, checking OS, browser version, user-agent, screen size, etc.
* The landing page embedded Telegram Bot API credentials and chat identifiers to report victim data (IPs, geolocation, download activity) to an attacker bot.
* Targets were redirected to other attacker domains, including burnsworth.site and essaywritingservice.site, before downloading a malicious installer.
* These redirection pages collected public IP, location, ISP, coordinates, device type, browser details, user-agent, and UTC timestamp.
* The landing page delayed the automatic download, requiring an action to trigger the payload download.
* A malicious ScreenConnect installer was downloaded from hamham27.screenconnect.com.
* The installer reused parameters across variants (e.g., Access&y=Guest) and downloaded initial RMM clients, which in turn established secondary clients.
* One initial client executed a script that deployed another installer, often involving the uninstallation of the first client to evade detection.
* Post-deployment actions included executing HideULx64.exe and creating scheduled tasks to run scripts.

Full Take

The narrative highlights a profound vulnerability in trusting domain reputation when services are repurposed as attack infrastructure. The exploitation hinges on the trust placed in Microsoft's legitimate domain structure, which effectively bypasses standard email security gateways. Attackers leverage this trust not just for delivery but for establishing an initial beachhead that appears benign.
A critical pattern emerges in the use of layered reconnaissance. The initial phishing lure is designed to get the victim to initiate an action within a trusted context, while the subsequent landing pages operate as sophisticated fingerprinting mechanisms designed specifically to filter out automated security analysis and focus on human victims—this is a form of deliberate noise generation designed for evasion. Furthermore, the reuse of specific artifacts, such as identical ScreenConnect installer paths and session tokens across multiple incidents, suggests organized operational tradecraft rather than opportunistic attacks.
The persistence mechanism described—deploying multiple RMM instances and using automated scheduling combined with defense evasion tools—suggests a shift from simple initial compromise to establishing deep, multi-faceted control. The core implication is that monitoring endpoint behavior must extend beyond network ingress/egress to focus on the execution of post-download scripts, scheduled tasks, and the installation/interaction with remote access tools themselves. This necessitates a focus not only on blocking malicious domains but on analyzing anomalous activity *after* a seemingly benign file has been executed or a legitimate service interaction has occurred.
Bridge Questions: If trusted cloud services are successfully weaponized for delivery, how should security architecture prioritize continuous verification of internal process execution rather than just perimeter checks? What mechanisms are necessary to distinguish between legitimate session behavior and attacker-driven environmental fingerprinting when interacting with cloud-hosted content? How can endpoint detection and response systems be adapted to recognize the subtle behavioral signatures resulting from multi-stage RMM installation sequences, irrespective of the initial file hash or domain reputation?

From the original · Huntress Labs

Background Threat actors frequently abuse legitimate platforms in their phishing attacks in order to bypass email security measures and increase the believability of the attack. We recently saw attackers abusing Microsoft Power BI, a business intelligence and data visualization tool used to turn raw data into interactive reports, dashboards, and charts.
Read the full story at huntress.com

Sentinel — Human

Confidence

This text reads like an aggregation of detailed incident response findings, demonstrating high technical specificity consistent with human forensic analysis rather than generalized AI generation.

Signals Detected
low severity: Slightly variable sentence length and technical specificity suggest human analysis or careful curation.
low severity: The flow from phishing lure to fingerprinting mechanism to payload delivery is logically structured, consistent with threat intelligence reporting.
low severity: Specific IOCs and technical steps are presented factually, characteristic of detailed forensic reporting rather than broad synthesis.
low severity: The text relies heavily on specific technical evidence (filenames, hashes, URLs) which implies direct source material review, reducing fabrication risk related to core claims.
Human Indicators
Inclusion of specific SHA256 hashes and internal file paths suggests reliance on actual forensic artifacts, not purely generated narrative.
The structure mimics a structured threat report format (Background, Attack, IOCs).
Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs | Huntaegis