DKDKCISSPSearch
Cyber AttacksDEVELOPING

Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs | Huntress

In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.

DKCISSP News DeskHuntress7 Oct 2026, 6:30 pm
Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs | Huntress
Image courtesy of Huntress. Original report
DKCISSP REPORT

In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.

Threat actors sent phishing emails with an embedded link that abused a legitimate Microsoft Power BI domain, which prompted targets to press a "Download Reference" button.

We recently saw attackers abusing Microsoft Power BI, a business intelligence and data visualization tool used to turn raw data into interactive reports, dashboards, and charts.

Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).

Threat actors have previously abused Power BI in phishing attacks by creating real dashboards on app.powerbi.com under their own (usually compromised or throwaway) account, embedding a malicious link into that dashboard, and setting the dashboard's sharing permissions to public before sending it to targets via email.

By abusing Microsoft Power BI, they hosted a convincing lure on a legitimate domain, then used a fake download prompt to install rogue ScreenConnect clients and establish persistent remote access.

These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference".

Figure 3: Screenshot from main.js showing the reuse of the Telegram bot This is classic anti-analysis and traffic filtering behavior, which is an attempt by attackers to weed out scanners and keep researchers from seeing the attack's payload; visitors who failed these checks would be redirected to check.vykyn[.]click/E/ .

Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers" to prevent an application from writing a vulnerable signed driver to disk.

What happened

In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.

Threat actors sent phishing emails with an embedded link that abused a legitimate Microsoft Power BI domain, which prompted targets to press a "Download Reference" button.

What changed

We recently saw attackers abusing Microsoft Power BI, a business intelligence and data visualization tool used to turn raw data into interactive reports, dashboards, and charts.

Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.

Who is affected

The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).

Threat actors have previously abused Power BI in phishing attacks by creating real dashboards on app.powerbi.com under their own (usually compromised or throwaway) account, embedding a malicious link into that dashboard, and setting the dashboard's sharing permissions to public before sending it to targets via email.

Why it matters

By abusing Microsoft Power BI, they hosted a convincing lure on a legitimate domain, then used a fake download prompt to install rogue ScreenConnect clients and establish persistent remote access.

These emails led victims to a fake reference document on the Power BI domains, which prompted targets to "Download Reference".

Technical details

Figure 3: Screenshot from main.js showing the reuse of the Telegram bot This is classic anti-analysis and traffic filtering behavior, which is an attempt by attackers to weed out scanners and keep researchers from seeing the attack's payload; visitors who failed these checks would be redirected to check.vykyn[.]click/E/ .

Microsoft also recommends turning on the Attack Surface Reduction (ASR) rule "Block abuse of exploited vulnerable signed drivers" to prevent an application from writing a vulnerable signed driver to disk.

Starting September 10, we saw this phishing campaign with the same delivery vector, ScreenConnect clients, and network Indicators of Compromise (IOCs) hit a handful of different endpoints.

Response

Defenders should review phishing protections and user-reporting workflows for links hosted on trusted cloud services, especially when they lead to downloads or request sensitive actions.

After deploying two rogue ScreenConnect clients, attackers also executed a defense evasion tool and scheduled tasks.

What security teams should do

Rather, commands are received via the extension, which houses three other modules - CERT-UA is advising organizations to prohibit regular users from using the Windows Run dialog via group policies, restrict the installation of MSI packages by users without administrator rights, monitor for the execution of "msiexec.exe," enable blocking of vulnerable drivers via Microsoft's vulnerable driver blocklist, and limit the installation of browser extensions to allowlisted ones.

What remains unknown

Across other incidents, we also saw the new browser tab opened to other attacker-controlled domains, including: The campaign variant hosted on the burnsworth[.]site/S/main.html page would fingerprint victims by collecting their public IP, IP-derived location and ISP, approximate coordinates, device type, browser and version, full user-agent, and UTC timestamp, while restricting access to Windows desktop systems and filtering Microsoft or unknown ISPs; it also reused the same hardcoded Telegram Bot API credential and chat identifier to report that telemetry.

Attribution

Huntress: In September, Huntress observed a phishing campaign where threat actors abused legitimate Power BI domains to make their attack more convincing and evade security controls that trust the service.

The Hacker News: The Computer Emergency Response Team of Ukraine (CERT-UA) has identified more than 100 compromised websites that have been injected with malicious JavaScript to serve an information-stealing malware called LunexStealer (aka Psychedelic Stealer).

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

MORE IN CYBER ATTACKS

More cybersecurity reporting

Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google DomainsThe Hacker News · 8 Oct 2026, 12:18 amWikimedia Says OpenAI Agents Tried to Compromise Etherpad and Use Wiki Tools as ProxiesThe Hacker News · 7 Oct 2026, 8:28 pmAttackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix LuresThe Hacker News · 30 Sept 2026, 9:22 pmRatHat's Evolving C2 Panel Points to Malware-as-a-Service Model - Infosecurity MagazineInfosecurity Magazine · 29 Sept 2026, 8:00 pm