RMM Phishing Campaign Hits 46 Countries, US as Primary Target
Attackers are weaponizing legitimate Remote Monitoring and Management (RMM) tools — software already trusted by IT teams — to bypass traditional security controls, making detection significantly harder than with custom malware. Victims are lured through convincing fake documents such as tax forms, invoices, and shipping notices, exploiting low security awareness around seemingly routine communications. The use of rapidly rotating, disposable infrastructure hosted on reputable platforms like Vercel allows attackers to evade blocklists and reputation-based defenses. This campaign highlights the dangerous intersection of social engineering and living-off-the-land techniques, where legitimate software becomes the attack vector. Organizations that fail to monitor RMM tool usage and employee phishing susceptibility are especially exposed.
Tactical Insight
Immediate actions
- Audit and whitelist approved RMM tools, blocking unauthorized installations or connections at the endpoint and network level.
- Deploy email security controls (DMARC, DKIM, SPF) and anti-phishing filters tuned to detect fake invoices, tax forms, and shipping lures.
- Alert on and investigate any RMM software initiating outbound connections to unknown or newly registered domains.
Long-term improvements
- Conduct regular, scenario-based phishing simulations that include document-lure themes (invoices, tax notices) to build employee recognition skills.
- Establish a formal application allowlisting policy that restricts which RMM tools can be installed and executed across the environment.
- Implement least-privilege access controls so that even if an RMM session is hijacked, lateral movement and privilege escalation are constrained.
Detection measures
- Centralize and correlate logs from endpoint detection tools and network sensors to flag anomalous RMM session initiations or unexpected geographic connections.
- Subscribe to threat intelligence feeds that track disposable infrastructure indicators (e.g., Vercel-hosted phishing domains) and push blocklists automatically.
- Establish a clear user reporting mechanism for suspicious emails and ensure SOC playbooks cover RMM-based intrusion scenarios.