Zero Day Room
Live
Defence

RMM Phishing Campaign Targets US, Spans 46 Countries

A global phishing campaign using fake documents to deploy legitimate remote monitoring and management software has made the United States its primary

A global phishing campaign using fake documents to deploy legitimate remote monitoring and management software has made...

A phishing campaign abusing legitimate remote monitoring and management (RMM) software has targeted 46 countries, with the United States now its top victim. According to research from ANY.RUN, 45% of the campaign's observed activity was associated with US targets, with 601 cases linked to the wider operation.

The attackers use a variety of fake document lures tailored to their victims, including shipping notices, Adobe PDFs, tax forms, Social Security Administration communications, and invoices. The goal is to trick recipients into installing RMM tools, which then grant the threat actors remote access. The campaign's infrastructure is highly disposable, making traditional detection difficult.

Infrastructure Rotates Daily

The campaign's delivery infrastructure changes much faster than its core attack methods. ANY.RUN researchers identified 425 kit URLs spread across 240 different hosts. A significant 94% of these hosts were observed for only a single day before being abandoned.

The operation has use multiple trusted platforms for hosting its phishing kits and payloads. The following table outlines the services used for delivery and payload staging, as identified in the source report.

Despite this rapid rotation, the phishing kit leaves behind more persistent forensic fingerprints. Shared assets like a specific font file (font1.woff2), recurring image resources, and a consistent delivery chain from secure.html to a project/*.zip file have allowed researchers to connect disparate infrastructure to the same overarching campaign.

Top Targeted Industries

The campaign casts a wide net across multiple sectors. Education, technology, and government entities are among the most frequently targeted industries. The banking and finance sector, along with manufacturing, are also prominent targets in this widespread phishing operation.

A key characteristic of the attack is the disposability of individual domains and specific RMM software brands. The underlying delivery chain and techniques, however, remain more stable. ANY.RRUN states this demonstrates why detection cannot rely solely on malware verdicts, domain reputation, or isolated indicators of compromise (IOCs).

Key Detection Takeaways for SOC Teams

The researchers outlined several recommendations for security operations center (SOC) teams to better defend against such threats. They advise building product-agnostic defenses, as legitimate software can be abused and attackers can easily switch between vendor tools. The focus should remain on detecting unauthorized remote-access activity and understanding the delivery chain.

Instead of relying only on blocklists of malicious domains, which change daily in this campaign, SOCs should prioritize more stable kit indicators. These include the font1.woff2 file, the icons8-microsoft-word-94.png asset, and the secure.html to project/*.zip delivery sequence.

Establishing stronger mail-layer controls and raising user awareness are also critical, especially as the campaign uses password-protected archives to deliver payloads. ANY.RUN emphasizes that analysts need full behavioral and threat context to respond effectively. Their interactive sandbox was used to expose the campaign's browser activity, scripts, and network behavior, while a threat intelligence lookup connected persistent indicators to related infrastructure.

As threat actors increasingly blend legitimate software, trusted services, and disposable infrastructure, security teams require deeper visibility to operationalize threat context and respond faster.

Related coverage

More from Defence