AI Security AI安全 4h ago Updated 2h ago 更新于 2小时前 40

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries 美国成为跨越46国家的RMM钓鱼攻击运动的首要目标

A large-scale RMM phishing campaign spanning 46 countries has identified the US as its top target, accounting for approximately 45% of observed activity Attackers use socially engineered fake documents (tax forms, shipping notices, Adobe PDFs, invoices) to trick victims into installing legitimate remote monitoring and management software The campaign employs rapidly rotated disposable infrastructure, with 94% of 240 identified hosts observed for only a single day Shared persistent fingerprints—i 针对46个国家的RMM钓鱼活动,美国占45%成为首要目标 攻击者利用伪造的税务文件、快递通知等诱骗受害者安装合法RMM软件 使用快速轮换的基础设施(94%主机仅存活一天),增加追踪难度 教育、科技、政府、金融和制造业是主要目标行业 攻击者通过共享资源指纹和稳定的交付链保持持续性

58
Hot 热度
62
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • A large-scale RMM phishing campaign spanning 46 countries has identified the US as its top target, accounting for approximately 45% of observed activity
  • Attackers use socially engineered fake documents (tax forms, shipping notices, Adobe PDFs, invoices) to trick victims into installing legitimate remote monitoring and management software
  • The campaign employs rapidly rotated disposable infrastructure, with 94% of 240 identified hosts observed for only a single day
  • Shared persistent fingerprints—including specific font files, image assets, and a consistent delivery chain structure—enabled researchers to connect 601 cases to the same operation
  • Detection strategies must shift from relying on individual IOCs and domain reputation toward analyzing behavioral patterns and delivery chain indicators

Why It Matters

This campaign exemplifies the growing trend of "living-off-the-land" attacks where threat actors abuse legitimate software tools to bypass traditional security controls, making detection significantly more challenging for security teams. The rapid infrastructure rotation combined with localized social engineering lures demonstrates how adversaries are adapting to evade detection while maintaining high conversion rates across diverse geographic and industry targets.

Technical Details

  • The campaign leverages legitimate RMM software as the primary payload, distributed through phishing pages mimicking trusted entities such as the Canada Revenue Agency, US Social Security Administration, UPS, and Adobe
  • Infrastructure includes 425 kit URLs across 240 hosts, with delivery platforms spanning Vercel, GitHub Pages, Netlify, Amazon S3, Cloudflare R2, DigitalOcean Spaces, Dropbox, and GoFile
  • Persistent forensic indicators include the font file font1.woff2, the image asset icons8-microsoft-word-94.png, and a consistent secure.html → project/*.zip delivery chain structure
  • Targeted industries include education, technology, government, banking, finance, and manufacturing, with lures dynamically adapted to each geographic region
  • The attack chain combines password-protected archive delivery, browser-based exploitation, and unauthorized remote access, requiring behavioral analysis rather than signature-based detection to identify

Industry Insight

Security teams should adopt a product-agnostic defense posture that focuses on detecting unauthorized remote-access activity and delivery chain patterns rather than relying on individual domain reputations or malware verdicts, which are trivially evaded by daily infrastructure rotation. Organizations should implement mail-layer controls that account for password-protected archive delivery and enhance user awareness programs to recognize socially engineered lures targeting legitimate software installation. The campaign highlights the critical need for SOC teams to invest in interactive sandboxing and threat intelligence platforms that provide behavioral context and connect persistent indicators across dispersed infrastructure.

TL;DR

  • 针对46个国家的RMM钓鱼活动,美国占45%成为首要目标
  • 攻击者利用伪造的税务文件、快递通知等诱骗受害者安装合法RMM软件
  • 使用快速轮换的基础设施(94%主机仅存活一天),增加追踪难度
  • 教育、科技、政府、金融和制造业是主要目标行业
  • 攻击者通过共享资源指纹和稳定的交付链保持持续性

为什么值得看

这篇文章揭示了攻击者如何利用合法RMM软件进行大规模钓鱼攻击,为安全团队提供了重要的威胁情报和检测思路。

技术解析

  • 攻击基础设施:使用Vercel、GitHub Pages、Netlify等快速轮换平台,94%的主机仅存活一天,同时利用Amazon S3、Cloudflare R2、Dropbox等服务托管载荷
  • 钓鱼诱饵:伪造CRA税务表格、UPS快递通知、Adobe PDF、美国社会保障局主题、发票等多种文档类型,根据目标地区自适应调整
  • 持久性指纹:font1.woff2、icons8-microsoft-word-94.png、secure.html → project/*.zip交付结构帮助研究人员关联分散的基础设施
  • 目标行业:教育、科技、政府、银行、金融、制造业

行业启示

  • 安全团队需要建立产品无关的防御策略,关注交付链和未经授权的远程访问活动,而非仅依赖恶意软件判定或域名信誉
  • 检测应围绕活动模式而非单一域名,优先关注稳定的工具指标和交付链特征
  • 邮件层控制和用户意识提升同样重要,需要应对密码保护档案投递的攻击手法

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究