CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

A phishing link on Microsoft's own Power BI domain slips past mail filters and installs rogue ScreenConnect clients, then, in one incident, a script replaces the first remote-management tool with a second

Huntress: a Power BI-hosted phishing link installs rogue ScreenConnect clients; in one case a script removed the first

Analysis

Huntress describes a phishing campaign it has seen since 2026-09-10 in which an Outlook email carries a link that leads to a fake reference document on a legitimate Power BI domain (Huntress, 2026-10-07). Huntress notes that threat actors have previously abused Power BI in this way, building a real dashboard under an account of their own (usually compromised or throwaway), embedding a malicious link and setting its sharing to public, and that because the link points to Microsoft's real domain it passes Microsoft 365 mail filters and other gateways that trust that domain; it does not say how this campaign's page was set up (Huntress, 2026-10-07). A "Download Reference" button opens a new tab on an attacker domain that fingerprints the visitor (operating system, browser, automation indicators, cloud-provider cookies), reports victims to a Telegram bot and redirects visitors who fail its checks; after a delay a script clicks a hidden download link for a ScreenConnect installer (Huntress, 2026-10-07).

The installer deploys a first rogue ScreenConnect client, which establishes a second one pointed at different infrastructure (Huntress, 2026-10-07). In one incident the first client ran a command-shell script that launched a PowerShell script from the temp directory; that script downloaded and ran the installer for the second client and uninstalled the first, in a likely effort to evade detection, and a scheduled task re-ran it every two minutes before the attack was shut down (Huntress, 2026-10-07). After deployment the clients also ran a tool Huntress assessed as designed to hide the attacker's activity from the user and security software (Huntress, 2026-10-07). A handful of endpoints were hit from 2026-09-10, and the configuration of one of the rogue clients also appeared on 22 other endpoints in separate incidents (Huntress, 2026-10-07). The original email and lure wording are unknown.

Triage: ScreenConnect is legitimate where the organisation runs it; the discriminators are an instance that is not the organisation's own and an installer that arrived through a browser download from a web page rather than through IT's deployment tooling (Huntress, 2026-10-07).

Cited evidence

Because the link points to Microsoft's real Power BI domain, it skirts through Microsoft 365 mail filters and other security gateways that trust this domain.

the PowerShell script also resulted in the uninstallation of the first ScreenConnect instance, in a likely effort to evade detection

Huntress 2026-10-07

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.