Attackers Exploit Microsoft Power BI for Phishing Campaign
Recent research from Huntress has revealed alarming tactics employed by attackers who are manipulating Microsoft Power BI to distribute phishing lures. This strategy not only helps the attackers evade email security filters but also facilitates the installation of multiple rogue ScreenConnect clients on victims’ machines, thereby ensuring persistent remote access.
The malicious campaign was first identified on September 10, when attackers began using public Power BI dashboards hosted on Microsoft’s legitimate app.powerbi.com domain as the landing page for phishing emails sent through Outlook. Because this link resolves to a trusted Microsoft service, it effectively bypasses the filtering mechanisms of Microsoft 365 mail, as well as other secure email gateways that typically allow-list the domain. This clever exploitation of trusted services raises significant concerns about the reliability of existing email security measures.
Huntress recorded multiple instances of the phishing campaign targeting various endpoints that utilized the same delivery methods and underlying infrastructure. Upon conducting a retroactive threat hunt, researchers discovered that the ScreenConnect client and related configurations tied to one of the rogue remote monitoring management (RMM) instances had also affected 22 other endpoints, indicating that the campaign’s reach was broader than initially apparent.
Sophisticated Fingerprinting Tactics
The phishing experience begins when victims encounter a blurred, fake form that invites them to click a button labeled “Download Reference.” This action redirects users to an attacker-controlled website, featuring domains such as dailylifeproject[.]site, burnsworth[.]site, essaywritingservice[.]site, and openpediatrics[.]site. These websites employ advanced fingerprinting techniques to gather information about the visitor’s operating system, browser, screen size, user-agent, automation indicators, and cloud-provider cookies. Notably, one variant of the phishing site restricts access to Windows desktops and filters out users connected through Microsoft and unknown ISPs. This strategy effectively prevents scanners and researchers from accessing the malware’s payload. The collected telemetry data, which includes IP addresses and geolocation, is sent back to the attackers through a hardcoded Telegram bot, thereby allowing them to track the success of their campaign.
Within seconds of arriving at the phishing site, a hidden script automatically clicks a link to download a ScreenConnect installer. Meanwhile, the page falsely informs users that their “Reference Verification Form” has successfully downloaded. The installer is consistently sourced from the same ScreenConnect tenant across various campaign variants, with only the guest-access token differing—indicative of an attempt to maintain unique tracking for each lure.
Dual RMM Strategy
In a bid to create redundancy and evade potential detection, the attackers deploy a second rogue ScreenConnect client linked to separate infrastructure, specifically on the domain onthegotree[.]site. During one incident, a CMD file executed a PowerShell script named SCAutoFix.ps1, which installed this second client while uninstalling the first. Such tactics demonstrate the attackers’ sophistication and the lengths they are willing to go to avoid detection.
Huntress also reported observing the execution of a tool named HideUL_x64.exe, which is assessed as a defense evasion tool specifically designed to obfuscate malicious activity from both users and security software. Additionally, a scheduled task named SCAutoRepairEvery2Min was configured to execute the script every two minutes, ensuring continuous operation of the malicious software. The incident was ultimately halted when the Huntress Security Operations Center intervened to shut down the attack.
Recommendations for Organizations
In light of these developments, Huntress has issued several recommendations for organizations aiming to bolster their defenses against such phishing tactics:
- Review Phishing Protections: Organizations are urged to reassess their phishing protections and user-reporting workflows concerning links that originate from trusted cloud services, especially those leading to downloadable content.
- Monitor for Unexpected Installations: Vigilance is required for any new or unapproved ScreenConnect installations and connections to unauthorized ScreenConnect instances.
- Alert on Scheduled Tasks: Establish alerts for any scheduled tasks or scripts associated with remote access tools to catch potential threats before they escalate.
- Restrict Remote Management Software: It is advisable to limit the use of remote management software to approved instances and to investigate any endpoints exhibiting multiple RMM clients.
For a complete technical analysis and a detailed list of indicators of compromise, interested parties can refer to the comprehensive article on the Huntress blog.
This incident underscores the ongoing evolution of phishing campaigns and the need for organizations to remain vigilant in their cybersecurity practices.