
RMM Phishing Shifts to US as Primary Target Across 46 Countries
A global RMM phishing operation has pivoted to the United States as its primary target. Stable kit artifacts rather than domains enable tracking despite daily infrastructure rotation. Defenders must shift from IOC lists to behavioral delivery-chain detection.
The campaign began with Canadian tax lures but expanded rapidly. Attackers deploy fake UPS, Adobe, SSA, and invoice documents that prompt installation of commodity RMM software. ANY.RUN telemetry linked 425 kit URLs across 240 hosts, with 94% active for a single day only. Shared assets such as font1.woff2 and the secure.html to project zip delivery path provided the stable fingerprint that tied disparate hosts together despite infrastructure churn.
Evidence shows consistent abuse of trusted services including Vercel, Netlify, GitHub Pages, S3, Cloudflare R2, and Dropbox for payload staging. Education, technology, and government sectors lead the targeting list. The pattern mirrors prior legitimate-tool abuse campaigns documented by Proofpoint in 2024 and Red Canary’s 2025 RMM misuse reports, where detection focused on domain reputation failed once the kit itself remained constant.
Operational significance lies in the separation between disposable delivery assets and persistent behavioral indicators. SOC teams relying solely on malware signatures or single-domain blocks will continue to miss activity. The next phase will likely involve further rotation onto additional hosting platforms while preserving the same archive and font-based markers.
Independent verification of infrastructure overlap remains limited to sandbox telemetry; no state attribution has been asserted by researchers.
ANY.RUN: 20% increase in US-targeted RMM phishing cases within 45 days if Vercel and Netlify remain primary hosts.
Sources (2)
- [1]Primary Source(https://any.run/cybersecurity-blog/rmm-phishing-campaign-analysis/)
- [2]Supporting Source(https://www.proofpoint.com/us/threat-insight/post/rmm-abuse-campaigns-2024)