A coordinated phishing campaign targeting U.S. executives has stolen Microsoft 365 session tokens and deployed remote monitoring and management (RMM) tools to establish persistent access across corporate networks, according to research published by ANY.RUN.
The campaign, tracked across 351 sandbox submissions, concentrated 51% of its phishing emails on U.S. targets. Technology companies, manufacturing firms, government agencies, and consulting organizations absorbed the heaviest attack volume. Attackers leveraged the stolen sessions to bypass multi-factor authentication protections and gain control of executive email accounts, creating entry points for lateral movement and data theft.
The attack pattern combines two distinct phases. First, threat actors sent spear-phishing emails designed to deceive high-ranking employees into handing over credentials or clicking malicious links. Upon successful compromise, the attackers harvested active Microsoft 365 session tokens rather than simply capturing passwords. Session tokens bypass traditional MFA requirements because they represent already-authenticated connections to cloud services. Second, attackers deployed RMM tools like AnyDesk, TeamViewer, or custom remote access agents to establish persistence independent of the compromised email account. This dual approach ensures attackers retain footholds even after victims reset passwords or security teams revoke suspicious sessions.
The targeting of C-suite employees across multiple sectors reflects attacker sophistication. Executives typically maintain broad network permissions, control sensitive communications, and access financial systems. A compromised CFO or CTO account provides attackers with leverage for fraud, business email compromise (BEC) schemes, lateral movement to contractors and partners, and exfiltration of proprietary data. Manufacturing and government targets suggest potential espionage motivations alongside financial crime.
RMM tool deployment escalates risk substantially. Unlike compromised email accounts, which organizations can remediate by forcing password resets and revoking sessions, installed RMM agents persist across credential changes. They provide attackers with graphical interface access to systems, enabling them to execute commands, install additional malware, or exfiltrate files without relying on stolen credentials. This explains why RMM deployment appears as a standard second stage in this campaign.
Detection of this campaign required sandbox analysis because the initial phishing emails likely appeared contextually relevant to their targets. Attackers commonly impersonate trusted partners, vendors, or internal IT teams in executive-targeting campaigns. The phishing emails probably contained legitimate-looking branding, urgent language, and industry-specific details harvested from public sources or earlier reconnaissance.
Organizations should implement several defensive measures immediately. Deploy conditional access policies within Microsoft 365 to flag impossible travel scenarios, unusual session origins, and high-risk login patterns. Enforce hardware-based MFA tokens for executive accounts rather than relying solely on authenticator apps, which remain vulnerable to session interception. Monitor RMM tool installations through endpoint detection and response (EDR) solutions and establish an allow-list of approved remote access utilities. Mandate security awareness training with specific focus on executive targeting and phishing indicators. Implement email authentication standards including DMARC, SPF, and DKIM to reduce spoofing effectiveness.
Incident response teams should assume that any executive account showing unusual Microsoft 365 activity likely has associated RMM installations elsewhere on the network. Isolating the compromised account alone provides false confidence. Full network forensics and RMM tool discovery become necessary before restoring normal operations.
