hacker-news · Crawled Sep 3, 2026

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

4 IoCs
Read original article ↗

AI Summary

A widespread RMM phishing campaign has targeted 46 countries, with the United States now the top target, accounting for 45% of observed activity. Attackers use social engineering lures tailored to specific regions, including tax forms, shipping notices, and Adobe PDFs, to trick victims into installing legitimate remote monitoring and management (RMM) software for malicious purposes. The campaign leverages rapidly rotating infrastructure hosted on Vercel, GitHub Pages, Netlify, and other platforms, with 94% of domains active for only one day, complicating detection. Persistent artifacts such as shared resources (e.g., font1.woff2, icons8-microsoft-word-94.png) and a consistent delivery pattern (secure.html → project/*.zip) link disparate infrastructure to the same operation, indicating a coordinated and adaptive threat.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Filename font1.woff2 Details →
Filename icons8-microsoft-word-94.png Details →
Filename secure.html Details →
Filename project/*.zip Details →