US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
AI Summary
A widespread RMM phishing campaign has targeted 46 countries, with the United States now the top target, accounting for 45% of observed activity. Attackers use social engineering lures tailored to specific regions, including tax forms, shipping notices, and Adobe PDFs, to trick victims into installing legitimate remote monitoring and management (RMM) software for malicious purposes. The campaign leverages rapidly rotating infrastructure hosted on Vercel, GitHub Pages, Netlify, and other platforms, with 94% of domains active for only one day, complicating detection. Persistent artifacts such as shared resources (e.g., font1.woff2, icons8-microsoft-word-94.png) and a consistent delivery pattern (secure.html → project/*.zip) link disparate infrastructure to the same operation, indicating a coordinated and adaptive threat.
AI-extracted · verify before operational use