US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
A large-scale RMM phishing campaign spanning 46 countries has identified the US as its top target, accounting for approximately 45% of observed activity Attackers use socially engineered fake documents (tax forms, shipping notices, Adobe PDFs, invoices) to trick victims into installing legitimate remote monitoring and management software The campaign employs rapidly rotated disposable infrastructure, with 94% of 240 identified hosts observed for only a single day Shared persistent fingerprints—i
Analysis
TL;DR
- A large-scale RMM phishing campaign spanning 46 countries has identified the US as its top target, accounting for approximately 45% of observed activity
- Attackers use socially engineered fake documents (tax forms, shipping notices, Adobe PDFs, invoices) to trick victims into installing legitimate remote monitoring and management software
- The campaign employs rapidly rotated disposable infrastructure, with 94% of 240 identified hosts observed for only a single day
- Shared persistent fingerprints—including specific font files, image assets, and a consistent delivery chain structure—enabled researchers to connect 601 cases to the same operation
- Detection strategies must shift from relying on individual IOCs and domain reputation toward analyzing behavioral patterns and delivery chain indicators
Why It Matters
This campaign exemplifies the growing trend of "living-off-the-land" attacks where threat actors abuse legitimate software tools to bypass traditional security controls, making detection significantly more challenging for security teams. The rapid infrastructure rotation combined with localized social engineering lures demonstrates how adversaries are adapting to evade detection while maintaining high conversion rates across diverse geographic and industry targets.
Technical Details
- The campaign leverages legitimate RMM software as the primary payload, distributed through phishing pages mimicking trusted entities such as the Canada Revenue Agency, US Social Security Administration, UPS, and Adobe
- Infrastructure includes 425 kit URLs across 240 hosts, with delivery platforms spanning Vercel, GitHub Pages, Netlify, Amazon S3, Cloudflare R2, DigitalOcean Spaces, Dropbox, and GoFile
- Persistent forensic indicators include the font file
font1.woff2, the image asseticons8-microsoft-word-94.png, and a consistentsecure.html → project/*.zipdelivery chain structure - Targeted industries include education, technology, government, banking, finance, and manufacturing, with lures dynamically adapted to each geographic region
- The attack chain combines password-protected archive delivery, browser-based exploitation, and unauthorized remote access, requiring behavioral analysis rather than signature-based detection to identify
Industry Insight
Security teams should adopt a product-agnostic defense posture that focuses on detecting unauthorized remote-access activity and delivery chain patterns rather than relying on individual domain reputations or malware verdicts, which are trivially evaded by daily infrastructure rotation. Organizations should implement mail-layer controls that account for password-protected archive delivery and enhance user awareness programs to recognize socially engineered lures targeting legitimate software installation. The campaign highlights the critical need for SOC teams to invest in interactive sandboxing and threat intelligence platforms that provide behavioral context and connect persistent indicators across dispersed infrastructure.
Disclaimer: The above content is generated by AI and is for reference only.