US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
RMM phishing campaign targets US with 46 countries involved, using disposable infrastructure.
Summary
A broad phishing campaign, initially thought to target Canada, has expanded to 46 countries with the United States as the primary target. The campaign uses legitimate Remote Monitoring and Management (RMM) software, tricking victims with fake documents like tax forms, invoices, and shipping notices. Attackers leverage rapidly rotating, disposable infrastructure, primarily on Vercel, to evade detection, though shared assets provide persistent indicators.
Full text
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries The Hacker NewsSep 03, 2026Social Engineering / Malware An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software. The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect. US-First Threat with Daily Infrastructure Rotation Threat overview by ANY.RUN The campaign’s infrastructure changes significantly faster than its attack pattern. ANY.RUN researchers identified 425 kit URLs across 240 hosts, 94% of which were observed for only a single day. The operation has used Vercel, GitHub Pages, Netlify, compromised websites, and other infrastructure for delivery. Payloads have also been staged through services including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile. Despite this rapid rotation, the phishing kit leaves more persistent fingerprints. Shared assets such as font1.woff2, recurring image resources, and the secure.html → project/*.zip delivery structure helped researchers connect otherwise separate infrastructure to the same campaign. Education, technology, and government are among the top targeted industries. Banking, finance, and manufacturing are also prominently present. Attack chain overview by ANY.RUN Individual domains and RMM products are disposable, while the underlying delivery chain is more stable. This shows why detection cannot depend solely on malware verdicts, reputation, or individual IOCs. To detect these patterns and distinguish legitimate RMM use from abuse, SOC teams need access to the full behavioral context behind suspicious activity. Respond faster and reduce risk in your company with deeper visibility and intel from 16K+ organizations. Power your SOC with ANY.RUN Key Detection Takeaways for SOC Teams Build a product-agnostic defense: legitimate software can be abused and switched between vendors, leading to visibility gaps. Maintain focus on delivery chain and unauthorized remote-access activity. Detect around campaign patters: Instead of relying only on domains, which in this campaign get rotated daily, prioritize more stable kit indicators, including the fmtt / font1.woff2, icons8-microsoft-word-94.png asset, and the secure.html → project/*.zip chain. Establish mail-layer controls and raise user awareness: SOC teams should account for password-protected archive delivery. Give analysts behavioral and threat context: ANY.RUN's Interactive Sandbox exposed the campaign's browser activity, scripts, processes, downloads, and network behavior, while Threat Intelligence Lookup connected persistent indicators to related infrastructure and cases. One of the lures, an Adobe phishing page, analyzed within ANY.RUN Interactive Sandbox As attackers increasingly combine legitimate software, trusted services, and disposable infrastructure, security teams need to access and operationalize in-depth threat context. Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE Tweet Share Share Share SHARE Cloud security, Phishing, Remote Access, Social Engineering, Web Security ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control