RMM Phishing Campaign Spreads Across 46 Countries

ANY.RUN tied 601 phishing cases to a campaign that has spread across 46 countries, with about 45% of observed activity aimed at the United States. What first looked like Canada-focused tax lures turned out to be a wider operation using tailored documents such as shipping notices, invoices, and social security themes to pull victims in. Instead of dropping a malicious file, the lure pushes the victim to install legitimate remote monitoring and management (RMM) software themselves. Once that software is on the machine, the attacker can use its real remote-access channel, while rapidly rotated Vercel-hosted infrastructure and other disposable services make simple domain blocking and single-IOC hunting much less effective. For defenders, the exposure sits in the delivery chain as much as in any endpoint alert: if trusted remote-admin tools are allowed in the environment, a phishing click can become hands-on access without ever looking like malware. The campaign's churn also means the same abuse pattern can survive even when individual URLs and hosts disappear.

Part of the PlainSec briefing for 2026-09-03

Every edition of this story: RMM Phishing Campaign Spreads Across 46 Countries

Sources