The financially motivated CSuite operation targeted organizations in the United States and Europe with multi-stage phishing campaigns that steal credentials and Microsoft 365 sessions or install legitimate remote-management software for persistent endpoint access. Attackers impersonated trusted services including Adobe, DocuSign, Zoom, SharePoint, Teams, Microsoft 365 voicemail, Dropbox, and Google Meet, using device-code OAuth authentication phishing alongside credential-harvesting pages to bypass conventional password-focused defenses.
Investigators linked the identity-theft and remote-access branches through shared delivery infrastructure, phishing panels, operator accounts, and remote-administration systems. The CSuite v1.1 panel exposed records for 216 Chameleon phishing victims, 29 captured Microsoft 365 sessions, 1,593 Adobe lure documents, and 15,955 harvested email addresses; 60% of identified victims were US-based. The campaign used hijacked Adobe Document Cloud tenants, Cloudflare Workers, public code-hosting services, and tools including ScreenConnect, Action1, Atera, Syncro, and PDQ Connect, enabling business-email compromise, payment fraud, and durable access while rotating infrastructure and applying anti-analysis controls.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
CSuite-related feeds remained active through at least 3 September 2026, confirming the operation continued after the identified infrastructure-linking error.
An operator sent hosting-control-panel credentials and, three hours later, remote-desktop-host credentials to the same recipient. The remote desktop host administered the CSuite v1.1 panel, registrar, and Cloudflare account, linking the delivery and credential-capture infrastructure.
The earliest identified sample associated with the CSuite operation was dated 6 March 2026.
CSuite, a financially motivated phishing, credential-theft, Microsoft 365 session-hijacking, and remote-access operation, was observed targeting organizations beginning in February 2026.
Technical reporting described CSuite as a provider-and-affiliate operation and documented its use of legitimate remote-management tools, credential phishing, session theft, persistence mechanisms, and anti-bot-filtered lure infrastructure. The reporting identified 216 Chameleon victims, 29 captured Microsoft 365 sessions, 1,593 lure documents, and 15,955 collected email addresses, along with victim examples and additional infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 121 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourceany.run
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.