Power BI phishing campaign drops rogue ScreenConnect clients

Attackers are abusing Microsoft Power BI to host phishing lures that slip past email security, before dropping multiple rogue ScreenConnect clients on victims’ machines to secure persistent remote access, according to new research from Huntress. The campaign, first observed on 10 September, uses public Power BI dashboards on Microsoft’s legitimate app.powerbi.com domain as the landing […]

This article has been indexed from IT Security Guru

Read the original article: