tr-26-140-001 (1)

31153692894?profile=RESIZE_400xThese attacks are abusing trusted remote access tools to bypass detection, exposing a growing security gap for enterprises.  A fake Word Online phishing page has exposed a growing enterprise blind spot: attackers using trusted tools to gain remote access without raising immediate alarms.  

The attack chain observed by ANY.RUN moved from an Outlook email to an MSI installer, silent execution, ScreenConnect remote access, and HideUL-based concealment.  For CISOs, this is a warning that phishing in