← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

RMM Phishing Campaign Targets 46 Countries, with US as Primary Target

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • RMM phishing campaign spans 46 countries.
  • 45% of activity targets the United States.
  • Uses fake documents to install legitimate RMM software.
  • Infrastructure rotates daily to avoid detection.

Global Reach of RMM Phishing

A remote monitoring and management (RMM) phishing campaign, initially identified for targeting Canada, has been found to operate across 46 countries. Research by ANY.RUN indicates that the United States is the primary target, accounting for approximately 45% of the observed malicious activity. The campaign involves 601 cases where victims are lured into installing legitimate RMM software through deceptive documents.

Evolving Lures and Infrastructure

Attackers adapt their phishing lures to specific targets, utilizing themes such as shipping communications, Adobe PDFs, tax notices, US Social Security Administration documents, and invoices. The campaign employs rapidly rotating, disposable infrastructure, including Vercel, GitHub Pages, and Netlify, making it difficult to track. Payloads are also staged through services like Amazon S3, Cloudflare R2, and Dropbox.

Detection Challenges and Targeted Sectors

Despite the rapid rotation of infrastructure, shared assets and delivery structures provide persistent fingerprints for researchers to connect disparate activities. The campaign primarily targets industries such as education, technology, and government, with banking, finance, and manufacturing also significantly affected. The use of legitimate software and disposable domains highlights the need for detection strategies that go beyond traditional malware verdicts or individual indicators of compromise.

Recommendations for SOC Teams

Security Operations Center (SOC) teams are advised to build product-agnostic defenses, focusing on the delivery chain and unauthorized remote-access activity rather than specific software vendors. Detecting campaign patterns, rather than relying solely on individual indicators, is crucial for identifying and mitigating this evolving threat. Access to full behavioral context behind suspicious activity is essential for distinguishing legitimate RMM use from abuse.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 21 stories · Sep 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A phishing campaign using fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software has expanded to 46 countries, with 45% of observed activity targeting the United States. The campaign uses rapidly rotating infrastructure and varied lures to evade detection, impacting sectors like education, technology, and government.