International Cyber Expo International Cyber Expo
  • About Us
Wednesday, 7 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Power BI phishing campaign drops rogue ScreenConnect clients

Huntress researchers say attackers are hosting lures on a trusted Microsoft domain to bypass email filters, then layering remote access tools to keep their foothold

by Guru Writer
October 7, 2026
in Featured
Power BI phishing campaign drops rogue ScreenConnect clients
Share on FacebookShare on Twitter

Attackers are abusing Microsoft Power BI to host phishing lures that slip past email security, before dropping multiple rogue ScreenConnect clients on victims’ machines to secure persistent remote access, according to new research from Huntress.

The campaign, first observed on 10 September, uses public Power BI dashboards on Microsoft’s legitimate app.powerbi.com domain as the landing page for Outlook phishing emails. Because the link resolves to a trusted Microsoft service, it can bypass Microsoft 365 mail filtering and other secure email gateways that allow-list the domain.

Huntress observed the campaign hit a handful of endpoints using the same delivery method and infrastructure. A retroactive threat hunt then found that the ScreenConnect client and configuration tied to one of the rogue RMMs had also affected 22 other endpoints across separate incidents.

Fingerprinting before the payload

Victims land on a blurred fake form inviting them to “Download Reference”. Clicking the button opens a new tab to an attacker-controlled site, including dailylifeproject[.]site, burnsworth[.]site, essaywritingservice[.]site and openpediatrics[.]site.

These pages fingerprint the visitor’s operating system, browser, screen size, user-agent, automation indicators and cloud-provider cookies, with one variant restricting access to Windows desktops and filtering out Microsoft and unknown ISPs. Visitors who fail the checks are redirected away, a classic technique for keeping scanners and researchers from reaching the payload. The malware sends victim telemetry, including IP address and geolocation, to the operators via a hardcoded Telegram bot.

After a few seconds, a script programmatically clicks a hidden link to download a ScreenConnect installer, while the page tells the user their “Reference Verification Form” has downloaded successfully. The installer is pulled from the same ScreenConnect tenant across campaign variants, with only the guest-access token changing (observed values include ILEAYEASAN, PERFECTO and PAPASUPE), suggesting per-lure tracking.

Two RMMs are better than one

Rather than relying on a single foothold, the attackers deploy a second rogue ScreenConnect client connected to separate infrastructure (onthegotree[.]site). In one incident, a CMD file launched a PowerShell script, SCAutoFix.ps1, which installed the second client and then uninstalled the first, likely to evade detection.

Huntress also observed the execution of HideUL_x64.exe, assessed as a defence evasion tool designed to conceal activity from users and security software, and a scheduled task, SCAutoRepairEvery2Min, configured to re-run the script every two minutes. The Huntress SOC shut down the attack at this point.

Recommendations for defenders

Huntress advises organisations to:

  • Review phishing protections and user-reporting workflows for links hosted on trusted cloud services, particularly those that lead to downloads.
  • Monitor for new or unexpected ScreenConnect installations and connections to unapproved ScreenConnect instances.
  • Alert on scheduled tasks or scripts associated with remote access tools.
  • Restrict remote management software to approved instances and investigate endpoints with multiple RMM clients installed.

Full technical analysis and indicators of compromise are available on the Huntress blog: https://www.huntress.com/blog/screenconnect-power-bi

ShareTweet
Previous Post

The trust gap that AI watermarking can’t close

Recent News

Power BI phishing campaign drops rogue ScreenConnect clients

Power BI phishing campaign drops rogue ScreenConnect clients

October 7, 2026
The trust gap that AI watermarking can’t close

The trust gap that AI watermarking can’t close

October 7, 2026
Middle managers want tighter human oversight of AI than their bosses, TeamViewer research finds

Middle managers want tighter human oversight of AI than their bosses, TeamViewer research finds

October 7, 2026
Verify it, don’t assume it: why untested security controls are making life easy for attackers

Verify it, don’t assume it: why untested security controls are making life easy for attackers

October 7, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol