[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLRJDukfj8AhFa9Ul1dast6XriMdfFa27gy0KBkA3FdA":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"b1b78168-abde-47f8-b978-04435c3114f7","rmm-phishing-campaign-hits-46-countries-us-as-primary-target","d39caceb-0943-4068-bb9a-1b7fceb9693d","RMM Phishing Campaign Hits 46 Countries, US as Primary Target","Attackers are weaponizing legitimate Remote Monitoring and Management (RMM) tools — software already trusted by IT teams — to bypass traditional security controls, making detection significantly harder than with custom malware. Victims are lured through convincing fake documents such as tax forms, invoices, and shipping notices, exploiting low security awareness around seemingly routine communications. The use of rapidly rotating, disposable infrastructure hosted on reputable platforms like Vercel allows attackers to evade blocklists and reputation-based defenses. This campaign highlights the dangerous intersection of social engineering and living-off-the-land techniques, where legitimate software becomes the attack vector. Organizations that fail to monitor RMM tool usage and employee phishing susceptibility are especially exposed.","**Immediate actions:**\n- Audit and whitelist approved RMM tools, blocking unauthorized installations or connections at the endpoint and network level.\n- Deploy email security controls (DMARC, DKIM, SPF) and anti-phishing filters tuned to detect fake invoices, tax forms, and shipping lures.\n- Alert on and investigate any RMM software initiating outbound connections to unknown or newly registered domains.\n\n**Long-term improvements:**\n- Conduct regular, scenario-based phishing simulations that include document-lure themes (invoices, tax notices) to build employee recognition skills.\n- Establish a formal application allowlisting policy that restricts which RMM tools can be installed and executed across the environment.\n- Implement least-privilege access controls so that even if an RMM session is hijacked, lateral movement and privilege escalation are constrained.\n\n**Detection measures:**\n- Centralize and correlate logs from endpoint detection tools and network sensors to flag anomalous RMM session initiations or unexpected geographic connections.\n- Subscribe to threat intelligence feeds that track disposable infrastructure indicators (e.g., Vercel-hosted phishing domains) and push blocklists automatically.\n- Establish a clear user reporting mechanism for suspicious emails and ensure SOC playbooks cover RMM-based intrusion scenarios.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 9 – Email and Web Browser Protections","CIS Control 14 – Security Awareness and Skills Training","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 AC-17 – Remote Access","NIST SP 800-53 AT-2 – Security Awareness Training","NIST SP 800-53 AU-6 – Audit Record Review, Analysis, and Reporting","NIST CSF DE.CM-1 – Network Continuous Monitoring","MITRE ATT&CK T1219 – Remote Access Software","MITRE ATT&CK T1566 – Phishing","GDPR Article 32 – Security of Processing (for EU-adjacent orgs handling personal data)","published","2026-09-03T14:22:41.082894+00:00","2026-09-03T14:22:40.785+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fus-becomes-top-target-in-rmm-phishing.html","us-becomes-top-target-in-rmm-phishing-campaign-spanning-46-countries-54e49c","US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]