MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 15 h ago, last 15 h ago, peak #5

Hackers Abuse Microsoft Power BI to Deploy Rogue Remote Access Tools

Original: (huntress.com) Threat Actors Abuse Microsoft Power BI in Phishing Campaign to Deploy Rogue ScreenConnect RMM Clients In

Security firm Huntress reports a phishing campaign in which attackers abuse legitimate Microsoft Power BI domains to bypass email security filters and trick users into installing rogue ScreenConnect remote monitoring and management clients. Because the malicious links come from trusted Microsoft infrastructure, they evade common detection methods. Cybersecurity researchers are warning organizations to scrutinize Power BI sharing invitations and monitor for unauthorized ScreenConnect installations.

Why now: The abuse of trusted Microsoft domains to deliver remote access malware is a novel and concerning phishing technique.

HuntressMicrosoft Power BIScreenConnect

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1364607