CSuite is a financially motivated, multi-stage phishing and remote-access operation active from February through at least September 2026. It primarily targets organizations in the United States and Europe, including managed service providers, technology companies, government and administrative bodies, consulting firms, manufacturers, educational institutions, healthcare organizations, non-profits, and mortgage-related entities. CSuite operates through a provider-and-affiliate model in which shared operators supply phishing infrastructure, domains, hosting, and remote-management tooling while affiliates may use separate data-exfiltration endpoints. CSuite conducts credential phishing, Microsoft 365 session theft, and attacker-initiated device-code OAuth phishing. Its lures impersonate widely used enterprise services and document-sharing platforms, and it uses compromised mailboxes, SMTP relays, and hijacked document-sharing tenants to distribute messages. Captured credentials, authenticated sessions, and OAuth tokens enable mailbox access, business email compromise, payment-redirection fraud, follow-on phishing, and remote email collection. The operation delivers legitimate remote-management and endpoint-management products, including ScreenConnect, Action1, Atera, Syncro, PDQ Connect, Datto, LogMeIn Rescue, FleetDeck, SimpleHelp, and UltraVNC, often masqueraded as trusted business software or documents. Installation workflows use scripts, elevated execution, and Windows Installer to deploy agents. CSuite has established durable endpoint access through management-agent services and authentication components configured to load at startup, including in Safe Mode with Networking. CSuite employs layered anti-analysis and victim-screening controls, including bot and security-tool detection, IP and geographic filtering, browser-fingerprint and interaction checks, reCAPTCHA scoring, honeypot fields, browser-inspection deterrents, and resource-exhaustion logic. It uses cloud-hosted infrastructure, reverse proxies, public code hosting, shared hosting, and compromised websites to stage or conceal phishing and payload-delivery operations. Visitor telemetry is relayed to operator-controlled messaging notifications. The operation is also known as csuite.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
31 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
79 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A financially motivated phishing and remote-access operation structured as an infrastructure supplier with affiliates. It targets organizations through Adobe, DocuSign, Zoom, SharePoint, Microsoft 365 voicemail, and related business-service lures; steals credentials and Microsoft 365 sessions; conducts device-code OAuth phishing; and deploys legitimate remote-management agents for persistent endpoint access. Stolen mailboxes are used for manual access, business-email compromise, invoice fraud, payment redirection, and follow-on phishing.
CSuite conducts phishing, remote-access, and credential-theft operations. It distributes renamed legitimate RMM tools through Adobe, DocuSign, Dotloop, Zoom, and Dropbox-themed lures; captures Microsoft 365 credentials and live sessions via conventional and device-code phishing; and uses installed management agents for persistent remote access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.