Ethical Hacking News
A recent RMM phishing campaign has been identified as the top threat in the US, exposing critical remote monitoring and management vulnerabilities. The campaign, which has been linked to 601 cases, has been observed to target a broad range of industries and organizations, highlighting the need for organizations to be proactive in their cybersecurity efforts.
The recent RMM phishing campaign targets a substantial number of countries, with the US being the primary target. The attackers use fake documents and communications to lure victims into installing legitimate RMM software. The campaign uses rapidly rotating, disposable infrastructure, making it hard to track and detect. The campaign has been linked to 601 cases, with 45% of observed activity associated with the US. The attackers use various tools and services to deliver payloads, including Amazon S3 and Cloudflare R2. The phishing kit leaves behind persistent fingerprints, such as shared assets and recurring image resources. The operation targets various industries, including education, technology, and government, as well as banking, finance, and manufacturing. Security teams need a holistic approach to detect and respond to this threat, focusing on the delivery chain and unauthorized remote-access activity. Organizations need to establish mail-layer controls, raise user awareness, and provide analysts with behavioral and threat context to detect and respond to this threat.
The recent cybersecurity news highlights a concerning RMM phishing campaign that has been identified to target a substantial number of countries, with the United States being identified as the primary target. This campaign is notable for its unique approach to luring victims into installing legitimate remote monitoring and management (RMM) software, using a wide variety of fake documents and communications, including those from shipping and UPS, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other documents.
According to the ANY.RUN researchers, the attackers have made use of rapidly rotating, disposable infrastructure, which has made the campaign harder to track and detect. This approach has also made it difficult for security teams to establish a clear understanding of the campaign's infrastructure and attack patterns, making it a challenge to detect and respond to the threat.
The campaign has been linked to 601 cases, and it has been observed that around 45% of the observed activity was associated with the United States, making it the primary geographic target of the campaign. The attackers have also used a variety of tools and services to deliver payloads, including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.
Despite the challenges posed by the rapid rotation of infrastructure, the phishing kit leaves behind more persistent fingerprints, such as shared assets, recurring image resources, and the secure.html → project/*.zip delivery structure, which have helped researchers connect otherwise separate infrastructure to the same campaign.
The operation has also been linked to various industries, including education, technology, and government, as well as banking, finance, and manufacturing. This broad reach highlights the need for organizations to be vigilant and proactive in their cybersecurity efforts.
In order to detect and respond to this threat, security teams need to adopt a more holistic approach that focuses on the delivery chain and unauthorized remote-access activity. By doing so, they can reduce the visibility gaps that can occur when relying solely on malware verdicts, reputation, or individual IOCs.
Furthermore, the campaign highlights the need for organizations to establish mail-layer controls and raise user awareness, as well as provide analysts with behavioral and threat context. This can be achieved through the use of interactive sandbox solutions, such as the ANYRUN Interactive Sandbox, which can expose the campaign's browser activity, scripts, processes, downloads, and network behavior.
The recent RMM phishing campaign serves as a stark reminder of the evolving nature of cyber threats and the importance of staying vigilant and proactive in our cybersecurity efforts. As attackers continue to adapt and evolve, security teams must be prepared to respond with equal agility and creativity, leveraging cutting-edge technologies and strategies to stay ahead of the threat.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Broad-and-Widespread-Phishing-Campaign-Targets-US-as-Primary-Geographic-Location-Exposing-Critical-Remote-Monitoring-and-Management-Vulnerabilities-ehn.shtml
https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
Published: Thu Sep 3 09:06:51 2026 by llama3.2 3B Q4_K_M