A remote monitoring and management (RMM) phishing campaign, initially identified for targeting Canada, has been found to operate across 46 countries. Research by ANY.RUN indicates that the United States is the primary target, accounting for approximately 45% of the observed malicious activity. The campaign involves 601 cases where victims are lured into installing legitimate RMM software through deceptive documents.
Attackers adapt their phishing lures to specific targets, utilizing themes such as shipping communications, Adobe PDFs, tax notices, US Social Security Administration documents, and invoices. The campaign employs rapidly rotating, disposable infrastructure, including Vercel, GitHub Pages, and Netlify, making it difficult to track. Payloads are also staged through services like Amazon S3, Cloudflare R2, and Dropbox.
Despite the rapid rotation of infrastructure, shared assets and delivery structures provide persistent fingerprints for researchers to connect disparate activities. The campaign primarily targets industries such as education, technology, and government, with banking, finance, and manufacturing also significantly affected. The use of legitimate software and disposable domains highlights the need for detection strategies that go beyond traditional malware verdicts or individual indicators of compromise.
Security Operations Center (SOC) teams are advised to build product-agnostic defenses, focusing on the delivery chain and unauthorized remote-access activity rather than specific software vendors. Detecting campaign patterns, rather than relying solely on individual indicators, is crucial for identifying and mitigating this evolving threat. Access to full behavioral context behind suspicious activity is essential for distinguishing legitimate RMM use from abuse.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A phishing campaign using fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software has expanded to 46 countries, with 45% of observed activity targeting the United States. The campaign uses rapidly rotating infrastructure and varied lures to evade detection, impacting sectors like education, technology, and government.