Back to Newsroom
Threat Intel

Fake Adobe and DocuSign Alerts Fuel Phishing Wave Hijacking Microsoft 365 Accounts

A US-heavy phishing operation nicknamed CSuite pairs stolen Microsoft 365 sessions with quiet installs of remote-access software, giving attackers a foothold on both the mailbox and the device behind it.

Fake Adobe and DocuSign Alerts Fuel Phishing Wave Hijacking Microsoft 365 Accounts

Security researchers have uncovered a large, US-heavy phishing operation — nicknamed CSuite — that combines credential theft with the installation of legitimate remote-management software, giving attackers a foothold on both employee mailboxes and their devices.

What happened

The campaign was traced across more than 350 separate sandbox investigations, with just over half originating from the United States and a further fifth from India; smaller pockets of activity turned up in the Philippines, Australia, the UK, Canada, and roughly two dozen other countries. Technology, manufacturing, government, and consulting organizations were hit hardest.

CSuite relies on convincing business lures — a shared document notice, a DocuSign envelope, a Zoom or Google Meet invite, a Dropbox link — that pass through anti-bot gating before landing on a spoofed sign-in or document page. In one documented case, attackers forged a DocuSign "review" email in the name of a law firm; in another, a fake Adobe licensing-update notice pushed victims toward a page that ultimately delivered a malicious archive.

From there, the operation splits in two directions. One path delivers an installer, archive, or lightweight script that quietly sets up a legitimate remote-monitoring-and-management (RMM) tool such as ScreenConnect or Action1 — turning a phishing click into hands-on-keyboard access to the victim's machine. In one analyzed case, a single script launched from an Adobe-themed lure elevated its own privileges and silently installed ScreenConnect. The other path skips the device entirely and goes straight for identity: credential-harvesting pages or device-code phishing flows designed to capture live Microsoft 365 sessions, handing attackers mailbox access without ever touching an endpoint.

Why it matters

Most phishing kits chase one prize — a password. CSuite is built to walk away with two: a working Microsoft 365 session and a remote foothold on the endpoint that received it. That combination lets an intrusion escalate quickly into several connected problems at once — a hijacked mailbox used to monitor payment threads and impersonate the account owner, invoice and payment fraud built on real internal correspondence, a persistent remote-access channel that outlives the original phishing email, and lateral phishing sent from a trusted internal address to colleagues and partners. Because the same campaign touches identity and endpoint at once, containment takes longer and pulls in more of the incident-response team than a routine credential-phishing case would.

What to do

  • Treat unexpected installers, archives, or scripts riding along with "document" or "e-signature" emails as suspicious by default, even when the branding (Adobe, DocuSign, Microsoft) looks legitimate.
  • Apply application allow-listing or alerting for RMM tools — ScreenConnect, Action1, and similar software — so an unauthorized install triggers a review instead of going unnoticed; these tools are legitimate in an IT context but shouldn't silently appear on end-user machines.
  • Harden Microsoft 365 against session and device-code theft: enforce phishing-resistant MFA where possible, monitor for impossible-travel or unusual sign-in patterns, and review conditional access policies for device-code and legacy auth flows.
  • Reconstruct suspected incidents end-to-end — lure, delivery, execution, and any follow-on tool install — rather than judging severity from a single flagged file or domain, since CSuite intrusions typically span both a mailbox and a device.
  • Keep detection tooling supplied with current indicators; infrastructure behind campaigns like this rotates quickly, and static blocklists fall out of date fast.
SHARE