🚨 US organizations are a primary target of CSuite.
The operation uses business-themed lures to steal M365 sessions or deliver RMM tools. The detection surface is the reused lure build: /m/js/utils.js or a byte-identical visitor-alert template recurs across the lure pages. See the attack chain with the SharePoint lure
👉 Full CSuite analysis, IOCs, and detection context
Post #1285
124

- ❤ 7
- 👍 5
- 🔥 5