Skip to content
Phishing Campaign Exploits Power BI to Deploy Rogue RMMs

Phishing Campaign Exploits Power BI to Deploy Rogue RMMs

First seen 7 Oct 2026, 15:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 18:57 UTC
  • •Attackers exploit Microsoft Power BI to bypass email security in phishing campaigns.
  • •Victims are directed to malicious sites that fingerprint their systems before downloading malware.
  • •Multiple rogue ScreenConnect clients are deployed to maintain persistent access.

A phishing campaign has been identified that abuses Microsoft Power BI to deliver rogue ScreenConnect remote monitoring and management (RMM) clients. The campaign, first observed on September 10, 2026, uses legitimate Power BI dashboards as phishing lures, allowing attackers to bypass email security measures. Victims receive Outlook phishing emails with links to a fake document hosted on a trusted Power BI domain. Clicking the 'Download Reference' button leads to an attacker-controlled site that performs extensive fingerprinting of the victim's system. The campaign has impacted multiple endpoints, with a retroactive threat hunt revealing 22 additional affected systems. Attackers deploy multiple RMM clients to maintain persistent access, employing techniques to evade detection. Huntress has shut down the attack, but organizations are advised to enhance their phishing protections and monitor for unexpected ScreenConnect installations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
Phishing campaign first observed
Attackers began using Microsoft Power BI dashboards to deliver rogue ScreenConnect clients via phishing emails.
Huntress
2026-10-07
Huntress reports on campaign
Huntress published findings detailing the phishing campaign and its impact on multiple endpoints.
Itsecurityguru

More articles in this cluster (2)

Common questions

What systems are affected by this campaign?
The campaign primarily targets systems running Windows, as indicated by the fingerprinting techniques used.
How can organizations protect themselves?
Organizations should enhance their phishing protections, review user-reporting workflows, and monitor for unexpected ScreenConnect installations.
What should I do if I suspect an infection?
Immediately disconnect the affected system from the network and investigate for unauthorized ScreenConnect installations.