news.mlab.sh
Back to the feed
threat-intel

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

High
Summary

A sophisticated phishing campaign, initially linked to Canada, has expanded to impact 46 countries, with the United States being the primary target. The attackers are leveraging fake documents and a rapidly rotating infrastructure to trick victims into installing legitimate remote monitoring and management (RMM) software, utilizing services like Vercel and disposable hosting platforms. Security teams need to move beyond simple malware detection and focus on understanding the entire delivery chain and user behavior to effectively mitigate the risk.

A phishing campaign originating in Canada has evolved into a widespread operation affecting 46 countries, with the United States accounting for 45% of observed activity. ANY.RUN researchers initially linked the campaign to Canada due to its use of Canada Revenue Agency (CRA) tax forms as lures. The attackers are utilizing a diverse range of documents – including shipping and UPS communications, Adobe PDFs, US Social Security Administration themes, and invoices – to entice victims into installing legitimate remote monitoring and management (RMM) software.

The campaign employs a rapidly rotating infrastructure, utilizing services such as Vercel, GitHub Pages, Netlify, compromised websites, and other disposable hosting platforms. Payloads are staged through services including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile. Despite this rapid rotation, the phishing kit leaves more persistent fingerprints, such as shared assets like font1.woff2 and recurring image resources, and a specific delivery structure (secure.html → project/*.zip).

Education, technology, and government are among the top targeted industries, with banking, finance, and manufacturing also prominently present. The campaign’s infrastructure changes significantly faster than its attack pattern, making detection challenging.

SOC teams need to build a product-agnostic defense, recognizing that legitimate software can be abused and switched between vendors. They should prioritize detecting around campaign patterns, focusing on stable kit indicators like font1.woff2, icons8-microsoft-word-94.png, and the secure.html → project/*.zip chain. Establishing mail-layer controls and raising user awareness are also crucial, particularly regarding password-protected archive delivery. Access to in-depth threat context, such as browser activity, scripts, processes, downloads, and network behavior (as exposed by ANYRUN’s Interactive Sandbox), and threat intelligence lookup connecting persistent indicators to related infrastructure and cases, is essential for effective mitigation.

Read the full article at The Hacker News