ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

RMM phishing campaign spans 46 countries, researchers say

ANY.RUN said a phishing operation that used fake tax, shipping and invoice documents to distribute legitimate remote monitoring software reached 46 countries, with the US accounting for about 45% of observed activity.

The Hacker News

ANY.RUN said the campaign first appeared to target Canada because it used Canada Revenue Agency tax forms, but its research linked the operation to 46 countries. It said the United States accounted for about 45% of observed activity and that it connected 601 cases to the wider campaign.

The attackers used fake documents to get victims to install legitimate remote monitoring and management software, according to ANY.RUN. The lures changed by target and included shipping and UPS messages, Adobe PDFs, tax notices, US Social Security Administration themes and invoices.

Researchers identified 425 kit URLs across 240 hosts, and they said 94% were seen for only a single day. ANY.RUN said the infrastructure changed faster than the attack pattern and that the operation used Vercel, GitHub Pages, Netlify and compromised websites for delivery.

Payloads were also staged through Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox and GoFile, according to the report. ANY.RUN said shared assets and a repeated delivery sequence tied separate infrastructure to the same campaign, and it said education, technology, government, banking, finance and manufacturing were among the targeted sectors.

Named in this story

Companies

ANY.RUN
said its researchers analysed the campaign
Vercel
was used for delivery infrastructure
Netlify
was used for delivery infrastructure
GitHub
was used to stage payloads
Dropbox
was used to stage payloads
GoFile
was used to stage payloads
UPS
had communications mimicked in the lures
Adobe
had PDFs used in the lures

Governments and agencies

Canada Revenue Agency
had tax forms used as the initial lure
US Social Security Administration
had themes used in the lures

Products and systems

GitHub Pages
was used for delivery infrastructure
Amazon S3
was used to stage payloads
Cloudflare R2
was used to stage payloads
DigitalOcean Spaces
was used to stage payloads

Places

United States
accounted for about 45% of observed activity
Canada
was where the campaign was first associated with targeting

How the source tells it

The piece mixed technical reporting with vendor promotion and urgent calls to adopt the author’s tools.

  • vendor boosterism product claims and repeated promotion of the publisher’s own platform
  • urgency imperative language pushing SOC teams to act faster and use fuller context
  • hype large campaign counts and capability claims were used as proof of value