Mmastodon TechnologyCybersecurity first seen 2 d ago, last 2 d ago, peak #5
Power BI phishing campaign abuses Microsoft domain to deliver ScreenConnect malware
Original: A Power BI phishing campaign uses Microsoft's real domain to install rogue ScreenConnect clients. Learn how it works and
Security researchers are warning about a phishing campaign that abuses Power BI to trick victims into installing a rogue ScreenConnect remote-access client. The attack leverages Microsoft's legitimate domain, making malicious links appear trustworthy and complicating detection. Researchers including Huntress have published guidance on how the scheme works and how organisations can block it.
Why now: The abuse of a genuine Microsoft domain for phishing makes the attack unusually convincing and relevant to anyone using Microsoft's business tools.
MicrosoftPower BIScreenConnectHuntress
Evidence
- A Power BI phishing campaign uses Microsoft's real domain to install rogue ScreenConnect clients. Learn how it works and how to block it. # PowerBI # Phishing # ScreenConnect # RMM # RemoteAccess # EmailSecurity # Huntress # CyberSecurity https:// securityonline.info/power-bi-p… · DailyCyberSecurity@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1578091