Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs | Huntress
In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.
In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.
Threat actors sent phishing emails with an embedded link that abused a legitimate Microsoft Power BI domain, which prompted targets to press a "Download Reference" button.
We recently saw attackers abusing Microsoft Power BI, a business intelligence and data visualization tool used to turn raw data into interactive reports, dashboards, and charts.
Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
Threat actors have previously abused Power BI in phishing attacks by creating real dashboards on app.powerbi.com under their own (usually compromised or throwaway) account, embedding a malicious link into that dashboard, and setting the dashboard's sharing permissions to public before sending it to targets via email.
By abusing Microsoft Power BI, they hosted a convincing lure on a legitimate domain, then used a fake download prompt to install rogue ScreenConnect clients and establish persistent remote access.
These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference".
Figure 3: Screenshot from main.js showing the reuse of the Telegram bot This is classic anti-analysis and traffic filtering behavior, which is an attempt by attackers to weed out scanners and keep researchers from seeing the attack's payload; visitors who failed these checks would be redirected to check.vykyn[.]click/E/ .
Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers" to prevent an application from writing a vulnerable signed driver to disk.
What happened
In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.
Threat actors sent phishing emails with an embedded link that abused a legitimate Microsoft Power BI domain, which prompted targets to press a "Download Reference" button.
What changed
We recently saw attackers abusing Microsoft Power BI, a business intelligence and data visualization tool used to turn raw data into interactive reports, dashboards, and charts.
Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.
Who is affected
The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
Threat actors have previously abused Power BI in phishing attacks by creating real dashboards on app.powerbi.com under their own (usually compromised or throwaway) account, embedding a malicious link into that dashboard, and setting the dashboard's sharing permissions to public before sending it to targets via email.
Why it matters
By abusing Microsoft Power BI, they hosted a convincing lure on a legitimate domain, then used a fake download prompt to install rogue ScreenConnect clients and establish persistent remote access.
These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference".
Technical details
Figure 3: Screenshot from main.js showing the reuse of the Telegram bot This is classic anti-analysis and traffic filtering behavior, which is an attempt by attackers to weed out scanners and keep researchers from seeing the attack's payload; visitors who failed these checks would be redirected to check.vykyn[.]click/E/ .
Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers" to prevent an application from writing a vulnerable signed driver to disk.
Starting September 10, we saw this phishing campaign with the same delivery vector, ScreenConnect clients, and network Indicators of Compromise (IOCs) hit a handful of different endpoints.
Response
Defenders should review phishing protections and user-reporting workflows for links hosted on trusted cloud services, especially when they lead to downloads or request sensitive actions.
After deploying two rogue ScreenConnect clients, attackers also executed a defense evasion tool and scheduled tasks.
What security teams should do
Rather, commands are received via the extension, which houses three other modules - CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of "msiexec.exe," enable blocking of vulnerable drivers via Microsoft's vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.
What remains unknown
Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.
Attribution
Huntress: In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.
The Hacker News: The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).
What to watch next
Watch for new exploitation reports and updated indicators of compromise.