Cyber News / Article / US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.
Around45% of observed activity was associated with the United States, making it the campaign's top geographic target.ANY.RUNresearch connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software.
The attackers adapt their lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents. Rapidly rotated, disposable Vercel infrastructure makes the campaign harder to track and detect.
The campaign’s infrastructure changes significantly faster than its attack pattern. ANY.RUN researchers identified425 kit URLs across 240 hosts, 94% of which were observed for only a single day.
The operation has used Vercel, GitHub Pages, Netlify, compromised websites, and other infrastructure for delivery. Payloads have also been staged through services including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.
Despite this rapid rotation, the phishing kit leaves more persistent fingerprints. Shared assets such asfont1.woff2, recurring image resources, and thesecure.html → project/*.zipdelivery structure helped researchers connect otherwise separate infrastructure to the same campaign.
Education, technology, and government are among the top targeted industries. Banking, finance, and manufacturing are also prominently present.
Individual domains and RMM products are disposable, while the underlying delivery chain is more stable. This shows why detection cannot depend solely on malware verdicts, reputation, or individual IOCs.
To detect these patterns and distinguish legitimate RMM use from abuse, SOC teams need access to the full behavioral context behind suspicious activity.
Respond faster and reduce risk in your company with deeper visibility and intel from 16K+ organizations.Power your SOC with ANY.RUN
As attackers increasingly combine legitimate software, trusted services, and disposable infrastructure, security teams need to access and operationalize in-depth threat context.
Related articles
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
4 days ago
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
7 days ago
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
7 days ago

