CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Microsoft Power BI

product · product:microsoft-power-bi single-source

Coverage
1
first 2026-10-08 → last 2026-10-08
Latest activity
2026-10-08
Huntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed…
Peak priority
notable
1 notable
Targets
·
no sector or region stated
Sources cited
1
1 hosts

Defender insights

What each entry about Microsoft Power BI tells a defender to do, newest first.

2026-10-08NOTABLEHuntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed the first

Exposure · triage · detection

Story timeline

  1. 2026-10-08A phishing link on Microsoft's own Power BI domain slips past mail filters and installs rogue ScreenConnect clients, then, in one incident, a script replaces the first remote-management tool with a second
    active-threatsHuntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed the first

Hunting pivots

Releases covered
Microsoft Power BI
ATT&CK techniques (6 across 5 tactics)

6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessPhishing: Spearphishing Link
  • ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell
  • PersistenceScheduled Task/Job: Scheduled Task
  • Privilege EscalationScheduled Task/Job: Scheduled Task
  • Command and ControlIngress Tool Transfer · Remote Access Tools

Initial Access TA0001

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

Execution TA0002

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

T1059.003Command and Scripting Interpreter: Windows Command Shell×1

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

Persistence TA0003

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

Privilege Escalation TA0004

T1053.005Scheduled Task/Job: Scheduled Task×1

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

T1219Remote Access Tools×1

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Evidence: 2026-10-08/power-bi-dashboard-phishing-rogue-screenconnect-clients · ATT&CK page ↗

Entries about Microsoft Power BI (1)

2026-10-08 · view entry permalink →

NOTABLENATOB2

A phishing link on Microsoft's own Power BI domain slips past mail filters and installs rogue ScreenConnect clients, then, in one incident, a script replaces the first remote-management tool with a second

Huntress describes a phishing campaign it has seen since 2026-09-10 in which an Outlook email carries a link that leads to a fake reference document on a legitimate Power BI domain (Huntress, 2026-10-07). Huntress notes that threat actors have previously abused Power BI in this way, building a real dashboard under an account of their own (usually compromised or throwaway), embedding a malicious link and setting its sharing to public, and that because the link points to Microsoft's real domain it passes Microsoft 365 mail filters and other gateways that trust that domain; it does not say how this campaign's page was set up (Huntress, 2026-10-07). A "Download Reference" button opens a new tab on an attacker domain that fingerprints the visitor (operating system, browser, automation indicators, cloud-provider cookies), reports victims to a Telegram bot and redirects visitors who fail its checks; after a delay a script clicks a hidden download link for a ScreenConnect installer (Huntress, 2026-10-07).

The installer deploys a first rogue ScreenConnect client, which establishes a second one pointed at different infrastructure (Huntress, 2026-10-07). In one incident the first client ran a command-shell script that launched a PowerShell script from the temp directory; that script downloaded and ran the installer for the second client and uninstalled the first, in a likely effort to evade detection, and a scheduled task re-ran it every two minutes before the attack was shut down (Huntress, 2026-10-07). After deployment the clients also ran a tool Huntress assessed as designed to hide the attacker's activity from the user and security software (Huntress, 2026-10-07). A handful of endpoints were hit from 2026-09-10, and the configuration of one of the rogue clients also appeared on 22 other endpoints in separate incidents (Huntress, 2026-10-07). The original email and lure wording are unknown.

Triage: ScreenConnect is legitimate where the organisation runs it; the discriminators are an instance that is not the organisation's own and an installer that arrived through a browser download from a web page rather than through IT's deployment tooling (Huntress, 2026-10-07).

Because the link points to Microsoft's real Power BI domain, it skirts through Microsoft 365 mail filters and other security gateways that trust this domain.

the PowerShell script also resulted in the uninstallation of the first ScreenConnect instance, in a likely effort to evade detection

Huntress 2026-10-07
threat08 Oct 04:53Zsingle-sourceOpen finding →
Sources: Huntress

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Threats1

Source distribution

  • huntress.com1 (100%)