RMM Phishing Campaign Zeroes In on US Targets
A phishing campaign spanning 46 countries uses fake documents to push RMM tools, with 45% of activity aimed at the US.
The phishing campaign that security researchers first tied to Canada because of its Canada Revenue Agency (CRA) tax form lures has proven to be far wider, stretching across 46 countries. New analysis from ANY.RUN shows the operation is now heavily focused on the United States, which accounts for roughly 45% of all observed activity.
US at the Center
ANY.RUN researchers connected 601 individual cases to the larger campaign, which tricks victims into installing legitimate remote monitoring and management (RMM) software through fake documents. The geographic distribution marks a notable shift from the initial Canadian focus, with the US emerging as the primary target among the 46 countries affected.
The lures are tailored to each victim group. Attackers have used shipping notifications, UPS communications, Adobe PDFs, tax notices, messages themed around the US Social Security Administration, invoices, and other document types to make their traps look credible.
Infrastructure Rotates Daily
The campaign's technical backbone changes far more quickly than its attack patterns. ANY.RUN identified 425 kit URLs across 240 hosts, and 94% of those hosts were only observed for a single day before being swapped out.
Delivery relies on a mix of legitimate services that are easy to spin up and discard. The researchers found the operation using Vercel, GitHub Pages, Netlify, and compromised websites to host its pages, while payloads were staged through Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.
Persistent Fingerprints
Despite the rapid rotation of domains and hosting, the phishing kit leaves behind more durable markers. Shared assets, including font1.woff2, recurring image resources, and the secure.html → project/*.zip delivery structure, allowed researchers to tie seemingly separate infrastructure back to the same operation. These stable indicators become critical when individual domains change too quickly to block effectively.
The kit's structure is consistent even as the lures vary, giving defenders a way to recognize the campaign beyond simple domain or IP blocking.
Targeted Industries
Education, technology, and government are among the top sectors being targeted, according to ANY.RUN's research. Banking, finance, and manufacturing also appear prominently in the victim profile.
Because the attackers abuse legitimate RMM software, the malicious activity hides in plain sight. The delivery chain – not the RMM product itself – is the tell, which complicates detection for security teams that rely on standard reputation checks.
Key Takeaways for SOC Teams
ANY.RUN's analysis offers specific guidance for defenders. The firm urges SOC teams to build product-agnostic defenses, since legitimate software can be abused and swapped between vendors, creating visibility gaps. Instead of focusing only on domains that rotate daily, teams should prioritize more stable kit indicators such as the fmtt / font1.woff2 asset, the icons8-microsoft-word-94.png image, and the secure.html → project/*.zip chain.
Mail-layer controls and user awareness are also emphasized, particularly around password-protected archive delivery. Analysts need behavioral and threat context: ANY.RUN's Interactive Sandbox exposed the campaign's browser activity, scripts, processes, downloads, and network behavior, while Threat Intelligence Lookup connected persistent indicators to related infrastructure and cases.
As attackers increasingly combine legitimate software, trusted services, and disposable infrastructure, security teams need to access and operationalize in-depth threat context.
— ANY.RUN research team
Why This Matters for Defenders
The campaign is a reminder that attackers are moving beyond malware that sets off obvious alarms. By co-opting trusted RMM tools and reputable cloud services, they can slip past defenses that look for known bad files or domains. For businesses, this suggests that security strategies centered on blocking specific IOCs may fall short, and that behavioral analysis and persistent indicator tracking could become more important in catching such operations.
Sources
- The Hacker News Original source
Continue Reading
FBI Opens Probe Into License Data Sale
A dark web service is selling 153M+ driver's license images, prompting an FBI inquiry.
Node.js Abuse Signals Shift in Malware Delivery
Threat actors are hijacking the trusted Node.js runtime to deliver malware, evading detection in targeted attacks since early 2026.
Ransom Refusal Exposes 8.8M in Airport Breach
Manchester Airports Group data leak exposes 8.8M records after refusing ransom.