Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems.

The campaign uses convincing document lures, rapidly changing hosting infrastructure, and signed software that can blend into normal IT activity.

A phishing campaign is turning familiar support software into a direct route into corporate systems. Rather than dropping a clearly malicious program, the operators persuade recipients to install legitimate remote monitoring and management, or RMM, tools that can give an outsider control of a computer.

The activity began with fake Canada Revenue Agency T4 tax documents, but its reach is far broader. The same document-delivery framework has used Social Security Administration notices, Adobe PDF prompts, invoices, VAT alerts, shipping messages, and shared-file themes to target victims across 46 countries.

Campaign overview (Source - Any.Run)
Campaign overview (Source – Any.Run)

Analysts at ANY.RUN identified the operation as a US-first campaign, with 45% of observed activity tied to the United States.

ANY.RUN said in a report shared with Cyber Security News (CSN) that North America represented 61% of observed family cases, while the figures indicate targeting rather than confirmed breaches.

The danger lies in the choice of payload. Signed remote-support software can look like normal administrative activity and may not trigger security products built to find known malware.

Once installed, it gives an attacker hands-on access that can be used to browse systems, run commands, or prepare a deeper intrusion.

The campaign has remained active since January 2026, and the researchers caution that observed samples likely understate its true reach.

Hackers Abuse Legitimate RMM Tools

The attack starts with an email that points to a short-lived page hosted on a trusted cloud platform or a compromised website. A tax form is only one lure.

The page resembles a document portal, gives the recipient an access code, and offers a password-protected ZIP archive that is harder for automated mail scanners to inspect.

After the victim extracts the archive and runs its Visual Basic script, PowerShell fetches an RMM installer. The campaign has used GoTo Resolve and LogMeIn Rescue in this arm, while related activity has used ScreenConnect, ConnectWise, and ITarian.

This flexible approach resembles previous LogMeIn Resolve abuse, where legitimate remote tools were configured for attacker-controlled access.

Family submitter geography (Source - Any.Run)
Family submitter geography (Source – Any.Run)

The operator adds several checks before serving the final stage. Browser and location details are collected, an hCaptcha challenge may appear, and some pages send information to Telegram to filter visitors.

A short delay before the download also makes automated analysis less useful, while a harmless online PDF may open to keep the victim focused on the supposed document.

Researchers recorded 425 kit URLs across 240 hosts between February 5 and July 29, 2026. Ninety-four percent of the hosts appeared for only one day, including 82 one-use Vercel applications.

Attack Chain (Source - Any.Run)
Attack Chain (Source – Any.Run)

The rapid churn reinforces findings from earlier Vercel phishing delivery, where platform reputation can help malicious links get past initial scrutiny.

Hackers Abuse Legitimate RMM Tools

Blocking a single RMM product or a handful of domains will not reliably stop this campaign because both can change quickly.

Defenders should treat an unexpected RMM installation as an alert, particularly when it follows a download from a new hosting page, a password-protected archive, or a script launched by a user from an unusual location.

Security teams should maintain an approved inventory of remote-access products and investigate any installation outside that list. Email controls and staff awareness training should explicitly cover access-code pages and password-protected ZIP files.

The advice aligns with guidance on several abused RMM tools, which stresses allowlists and attention to unusual execution paths.

Network Infrastructure of the campaign (Source - Any.Run)
Network Infrastructure of the campaign (Source – Any.Run)

Hunting should prioritize recurring components of the delivery kit and the page-to-archive flow, instead of relying only on disposable domains.

Reviewing PowerShell activity that downloads MSI files and correlating it with newly installed support software can reveal an intrusion before remote control is used more widely. It also helps teams recognize abuse even when a familiar application carries a valid signature.

That distinction matters for organizations in education, technology, government, banking, manufacturing, and finance, which appeared prominently in the observed data.

Employees should verify tax, invoice, and document requests through an independently known channel, not the link in an email, a lesson also reflected in finance-themed Vercel lures.

Indicators of comrpomise (IoCs):-

Type Indicator Description
Detection pattern */secure.html on *.vercel[.]app Campaign kit page pattern
Detection pattern */project/*.zip on *.vercel[.]app Password-protected archive delivery pattern
File path *img/font1.woff2 Shared web-font pivot associated with the wider campaign
URL pattern /ftx/<6-char slug>-<10-digit epoch>-<12-hex>/ Per-recipient path pattern on platform hosts
DOM pattern font-family:'fmtt'img/font1.woff2alt='PDF Icon'Access code Repeated phishing-kit page elements
Domain fillingconfirmation[.]vercel[.]app Representative lure deployment
Domain sharedconfirmationslip[.]vercel[.]app Representative lure deployment
Domain officialsummarybycra[.]vercel[.]app Representative lure deployment
Domain 2026t4form17718[.]vercel[.]app Representative lure deployment
Domain crataxsummary1007341[.]vercel[.]app Representative lure deployment
Domain statemendetailsfilessenderderf[.]netlify[.]app Representative lure deployment
Domain quavix[.]vu Throwaway domain with a malicious verdict at observation
Domain cevora[.]vu Throwaway domain with a malicious verdict at observation
Domain xorlira[.]vu Throwaway domain with a malicious verdict at observation
Domain voretix[.]icu Throwaway domain with a malicious verdict at observation
Domain wurel[.]sbs Throwaway domain with a malicious verdict at observation
Domain mornixa[.]cfd Throwaway domain with a malicious verdict at observation
Domain getdl[.]jorix[.]cyou Throwaway domain with a malicious verdict at observation
Domain pdfmarchlitestatementsscannedforyou[.]gixar[.]sbs Throwaway domain with a malicious verdict at observation
Domain reportstastementformarchreviewyourssaast[.]harnivo[.]cfd Throwaway domain with a malicious verdict at observation
Dynamic DNS host 54511[.]ddnsking[.]com Attacker-controlled kit host
Dynamic DNS host dxy43[.]ddnsking[.]com Attacker-controlled kit host
Dynamic DNS host dyb32[.]ddnsking[.]com Attacker-controlled kit host
Dynamic DNS host 67pon[.]swoop2[.]me Attacker-controlled kit host
Dynamic DNS host dcsi23[.]swoop2[.]me Attacker-controlled kit host
Dynamic DNS host ssi11[.]letsgo2[.]me Attacker-controlled kit host
Dynamic DNS host ddn3[.]net2me[.]me Attacker-controlled kit host
URL hxxps://commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msi Captured RMM MSI download
Domain mayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]com Payload-staging bucket
Domain openfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]com Payload-staging bucket
IP address and port 46.62.197[.]232:7000 Durable origin infrastructure
Domain hiltonheadislanddeals[.]com Compromised site serving kit path
Domain gonzalezjaramilloabogados[.]com Compromised site serving kit path
Domain mybcdc[.]ca Compromised site serving kit path
Domain taurusburgerco[.]com[.]au Compromised site serving kit path
Domain ypatellawoffice[.]ca Compromised site serving kit path
Domain electrical-sei[.]com Compromised site serving kit path
Domain herculescalgarymovers[.]ca Compromised site serving kit path
Domain quantechitsolutions[.]com Compromised site serving kit path
SHA-256 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead Lure index-page content hash
SHA-256 132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d498 secure.html gate-page content hash
SHA-256 51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7 Word-style image asset content hash

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign to Gain Remote Access appeared first on Cyber Security News.