Attackers are abusing Microsoft Power BI to host phishing lures that slip past email security, before dropping multiple rogue ScreenConnect clients on victims’ machines to secure persistent remote access, according to new research from Huntress. The campaign, first observed on 10 September, uses public Power BI dashboards on Microsoft’s legitimate app.powerbi.com domain as the landing The post Power BI phishing campaign drops rogue ScreenConnect clients appeared first on IT Security Guru.
First seen on itsecurityguru.org
Jump to article: www.itsecurityguru.org/2026/10/07/power-bi-phishing-campaign-drops-rogue-screenconnect-clients/
![]()

