#ParsedReport #CompletenessHigh
22-09-2026
CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access
https://any.run/cybersecurity-blog/csuite-attack-analysis/
Report completeness: High
Threats:
Device_code_phishing_technique
Csuite
Pdq_connect_tool
Screenconnect_tool
Action1_tool
Atera_tool
Syncro_tool
Chameleon
Cloaking_technique
Barracuda_tool
Centrastage_tool
Fleetdeck_tool
Simplehelp_tool
Ultra_vnc_tool
Spear-phishing_technique
Victims:
Technology, Manufacturing, Government and administration, Consulting, Education, Nonprofit organizations, Energy sector, Healthcare
Industry:
Healthcare, Energy, Government
Geo:
Portuguese, North korea, Russia, Canada, Syria, Iran, Australian, Philippines, Australia, French, Italian, United kingdom, China, United states
TTPs:
Tactics: 4
Technics: 27
IOCs:
File: 36
Command: 6
Domain: 67
Url: 7
IP: 18
Hash: 29
Soft:
Microsoft 365, DocuSign, Zoom, SharePoint, Cloudflare, Dropbox, Telegram, PDF Viewer, Adobe Acrobat, Microsoft Edge, have more...
Functions:
getVisitorInfo, callsactivateTrap, setTimeout
Win API:
RUN, Popup, PDF
Win Services:
WebClient
Languages:
javascript, php, powershell
Platforms:
arm
Post #32684
26