Decoding the world of cybersecurity

Phishing campaign hides behind Microsoft Power BI links

Huntress has uncovered a phishing campaign using legitimate Microsoft Power BI pages to reach victims before installing redundant ScreenConnect clients for persistent remote access.

Phishing campaign hides behind Microsoft Power BI links
Summary
  • Phishing emails send victims to content on Microsoft’s legitimate Power BI domain.
  • Attacker infrastructure fingerprints visitors before delivering ScreenConnect.
  • Two rogue ScreenConnect clients provide redundant remote access to compromised endpoints.

A phishing campaign uncovered by Huntress is using legitimate Microsoft Power BI pages as the first stage of an attack that ultimately installs attacker-controlled remote access software on victims’ computers.

Researchers first observed the activity in September, when phishing emails directed targets to content hosted on Microsoft’s genuine app.powerbi.com domain. Because the initial destination belongs to a widely used cloud service, links can benefit from reputation and trust decisions that would treat an unfamiliar attacker domain more cautiously.

The Power BI content presents what appears to be a reference document and invites the visitor to select “Download Reference”. Clicking the prompt opens a new browser tab connected to infrastructure controlled by the attacker rather than delivering a document directly from Microsoft.

Before sending the next payload, the attacker-controlled site fingerprints the visiting system. Huntress found that the page delays for several seconds and then uses a script to activate a hidden download link, triggering delivery of an installer for ConnectWise ScreenConnect.

ScreenConnect is legitimate remote-management software used by support teams and managed service providers. In this campaign, however, the attackers install unauthorised clients that give them remote control of the endpoint without relying on a custom remote access trojan.

Persistence is reinforced through duplication. Huntress observed two separate rogue ScreenConnect clients being deployed to affected systems, leaving a second access route available if one client is discovered and removed.

The attackers subsequently ran a defence-evasion tool and created scheduled tasks, extending their access beyond the original phishing interaction. During retrospective hunting, Huntress also identified the distinctive ScreenConnect client and configuration associated with one of the malicious installations on 22 additional endpoints across separate incidents.

Those additional detections should not be treated as proof that every machine was compromised through the same Power BI delivery chain. Huntress established reuse of the ScreenConnect configuration, while the full initial access sequence was reconstructed on the systems directly associated with the phishing campaign.

The Microsoft-hosted stage exploits one of the practical assumptions behind link-reputation filtering. Security gateways can assign greater confidence to established cloud platforms because those domains carry large volumes of legitimate corporate traffic and blocking them indiscriminately would interrupt normal business use.

Attackers can take advantage of that tolerance by placing documents, redirects or intermediary content on a genuine service before moving the victim to infrastructure they control. A filter evaluating only the first destination may therefore encounter a valid Microsoft domain rather than the website that later fingerprints the visitor and provides the installer.

Nothing in Huntress’s findings indicates that Microsoft Power BI itself was compromised. The service is being abused as part of the delivery chain, much as attackers have previously used legitimate document sharing, storage and collaboration platforms to add credibility to malicious messages.

The ScreenConnect stage creates another form of borrowed trust because the software has legitimate enterprise uses and may already appear elsewhere inside an organisation. Its presence alone cannot establish malicious activity without context around the authorised instance, configuration, installer source and associated persistence.

By combining a trusted Microsoft-hosted link with legitimate remote-management software, the attackers reduce the number of obviously malicious indicators available at the two points where conventional controls commonly make decisions. The campaign therefore depends less on disguising a suspicious domain or bespoke malware and more on turning familiar services into components of the attack path.

×