CyberSecurityNews

Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access


A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems.

The campaign uses convincing document lures, rapidly changing hosting infrastructure, and signed software that can blend into normal IT activity.

A phishing campaign is turning familiar support software into a direct route into corporate systems. Rather than dropping a clearly malicious program, the operators persuade recipients to install legitimate remote monitoring and management, or RMM, tools that can give an outsider control of a computer.

The activity began with fake Canada Revenue Agency T4 tax documents, but its reach is far broader. The same document-delivery framework has used Social Security Administration notices, Adobe PDF prompts, invoices, VAT alerts, shipping messages, and shared-file themes to target victims across 46 countries.

Campaign overview (Source – Any.Run)

Analysts at ANY.RUN identified the operation as a US-first campaign, with 45% of observed activity tied to the United States.

ANY.RUN said in a report shared with Cyber Security News (CSN) that North America represented 61% of observed family cases, while the figures indicate targeting rather than confirmed breaches.

The danger lies in the choice of payload. Signed remote-support software can look like normal administrative activity and may not trigger security products built to find known malware.

Once installed, it gives an attacker hands-on access that can be used to browse systems, run commands, or prepare a deeper intrusion.

The campaign has remained active since January 2026, and the researchers caution that observed samples likely understate its true reach.

The attack starts with an email that points to a short-lived page hosted on a trusted cloud platform or a compromised website. A tax form is only one lure.

The page resembles a document portal, gives the recipient an access code, and offers a password-protected ZIP archive that is harder for automated mail scanners to inspect.

After the victim extracts the archive and runs its Visual Basic script, PowerShell fetches an RMM installer. The campaign has used GoTo Resolve and LogMeIn Rescue in this arm, while related activity has used ScreenConnect, ConnectWise, and ITarian.

This flexible approach resembles previous LogMeIn Resolve abuse, where legitimate remote tools were configured for attacker-controlled access.

Family submitter geography (Source - Any.Run)
Family submitter geography (Source – Any.Run)

The operator adds several checks before serving the final stage. Browser and location details are collected, an hCaptcha challenge may appear, and some pages send information to Telegram to filter visitors.

A short delay before the download also makes automated analysis less useful, while a harmless online PDF may open to keep the victim focused on the supposed document.

Researchers recorded 425 kit URLs across 240 hosts between February 5 and July 29, 2026. Ninety-four percent of the hosts appeared for only one day, including 82 one-use Vercel applications.

Attack Chain (Source - Any.Run)
Attack Chain (Source – Any.Run)

The rapid churn reinforces findings from earlier Vercel phishing delivery, where platform reputation can help malicious links get past initial scrutiny.

Blocking a single RMM product or a handful of domains will not reliably stop this campaign because both can change quickly.

Defenders should treat an unexpected RMM installation as an alert, particularly when it follows a download from a new hosting page, a password-protected archive, or a script launched by a user from an unusual location.

Security teams should maintain an approved inventory of remote-access products and investigate any installation outside that list. Email controls and staff awareness training should explicitly cover access-code pages and password-protected ZIP files.

The advice aligns with guidance on several abused RMM tools, which stresses allowlists and attention to unusual execution paths.

Network Infrastructure of the campaign (Source - Any.Run)
Network Infrastructure of the campaign (Source – Any.Run)

Hunting should prioritize recurring components of the delivery kit and the page-to-archive flow, instead of relying only on disposable domains.

Reviewing PowerShell activity that downloads MSI files and correlating it with newly installed support software can reveal an intrusion before remote control is used more widely. It also helps teams recognize abuse even when a familiar application carries a valid signature.

That distinction matters for organizations in education, technology, government, banking, manufacturing, and finance, which appeared prominently in the observed data.

Employees should verify tax, invoice, and document requests through an independently known channel, not the link in an email, a lesson also reflected in finance-themed Vercel lures.

Indicators of comrpomise (IoCs):-

TypeIndicatorDescription
Detection pattern*/secure.html on *.vercel[.]appCampaign kit page pattern
Detection pattern*/project/*.zip on *.vercel[.]appPassword-protected archive delivery pattern
File path*img/font1.woff2Shared web-font pivot associated with the wider campaign
URL pattern/ftx/<6-char slug>-<10-digit epoch>-<12-hex>/Per-recipient path pattern on platform hosts
DOM patternfont-family:'fmtt'img/font1.woff2alt="PDF Icon"Access codeRepeated phishing-kit page elements
Domainfillingconfirmation[.]vercel[.]appRepresentative lure deployment
Domainsharedconfirmationslip[.]vercel[.]appRepresentative lure deployment
Domainofficialsummarybycra[.]vercel[.]appRepresentative lure deployment
Domain2026t4form17718[.]vercel[.]appRepresentative lure deployment
Domaincrataxsummary1007341[.]vercel[.]appRepresentative lure deployment
Domainstatemendetailsfilessenderderf[.]netlify[.]appRepresentative lure deployment
Domainquavix[.]vuThrowaway domain with a malicious verdict at observation
Domaincevora[.]vuThrowaway domain with a malicious verdict at observation
Domainxorlira[.]vuThrowaway domain with a malicious verdict at observation
Domainvoretix[.]icuThrowaway domain with a malicious verdict at observation
Domainwurel[.]sbsThrowaway domain with a malicious verdict at observation
Domainmornixa[.]cfdThrowaway domain with a malicious verdict at observation
Domaingetdl[.]jorix[.]cyouThrowaway domain with a malicious verdict at observation
Domainpdfmarchlitestatementsscannedforyou[.]gixar[.]sbsThrowaway domain with a malicious verdict at observation
Domainreportstastementformarchreviewyourssaast[.]harnivo[.]cfdThrowaway domain with a malicious verdict at observation
Dynamic DNS host54511[.]ddnsking[.]comAttacker-controlled kit host
Dynamic DNS hostdxy43[.]ddnsking[.]comAttacker-controlled kit host
Dynamic DNS hostdyb32[.]ddnsking[.]comAttacker-controlled kit host
Dynamic DNS host67pon[.]swoop2[.]meAttacker-controlled kit host
Dynamic DNS hostdcsi23[.]swoop2[.]meAttacker-controlled kit host
Dynamic DNS hostssi11[.]letsgo2[.]meAttacker-controlled kit host
Dynamic DNS hostddn3[.]net2me[.]meAttacker-controlled kit host
URLhxxps://commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msiCaptured RMM MSI download
Domainmayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]comPayload-staging bucket
Domainopenfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]comPayload-staging bucket
IP address and port46.62.197[.]232:7000Durable origin infrastructure
Domainhiltonheadislanddeals[.]comCompromised site serving kit path
Domaingonzalezjaramilloabogados[.]comCompromised site serving kit path
Domainmybcdc[.]caCompromised site serving kit path
Domaintaurusburgerco[.]com[.]auCompromised site serving kit path
Domainypatellawoffice[.]caCompromised site serving kit path
Domainelectrical-sei[.]comCompromised site serving kit path
Domainherculescalgarymovers[.]caCompromised site serving kit path
Domainquantechitsolutions[.]comCompromised site serving kit path
SHA-25641b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3eadLure index-page content hash
SHA-256132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d498secure.html gate-page content hash
SHA-25651f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7Word-style image asset content hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link