Security firm Huntress said it saw a phishing campaign in September that used a real Microsoft Power BI domain. Power BI is a tool that turns data into reports and charts. Emails carried a link to a fake reference document there. The page asked the reader to click "Download Reference". That opened a new tab on a site the attackers controlled. The site checked the visitor's browser and system, then started a download of ScreenConnect, a remote access program, set up by the attackers. Huntress said the campaign began on September 10 and hit a handful of endpoints. A later search found the same client setup on 22 other endpoints in separate incidents.
Huntress said it could not get the original email, so the exact lure text is unknown. It said attackers installed two rogue ScreenConnect clients, ran a tool meant to hide their activity, and in one case set a task to rerun a script every two minutes. The company's security operations team stopped that attack at that point. Huntress did not say how many organisations were hit overall, who is behind the campaign, or whether Microsoft has acted on the abused pages.
Mail filters often trust links to big cloud services, and Huntress said that is why this trick works. People who run software or IT should watch for new or unexpected ScreenConnect installs. Huntress also advises limiting remote access tools to approved servers and checking any machine that has more than one such tool.