Scworld
Phishing Campaign Exploits RMM Tools Across 46 Countries
Article Content
A phishing campaign targeting remote management and monitoring (RMM) platforms has been identified in 46 countries, with 45% of the activity concentrated in the United States. Research from Any.Run indicates that attackers use fake documents such as tax notices and shipping alerts to trick users into installing legitimate RMM software. The operation employs rapidly rotating infrastructure, utilizing services like Vercel, GitHub Pages, and compromised websites for delivery. The campaign has been linked to 601 cases, with 425 kit URLs across 240 hosts, 94% of which were live for only a single day. This method complicates detection as the final payload consists of trusted software, making it difficult for security measures to flag unauthorized installations. Industries targeted include education, technology, and government, with a focus on banking and finance as well. Experts recommend treating RMM enrollment with the same caution as creating administrator accounts and implementing strict monitoring for unexpected remote-control service installations.
Key Points: • Phishing campaign targets RMM platforms in 46 countries, primarily the US. • Attackers use legitimate software to bypass security measures. • Rapidly rotating infrastructure complicates detection and response.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.