Cybersecurity
RMM phishing campaign spans 46 countries, researchers say
ANY.RUN said a phishing operation that used fake tax, shipping and invoice documents to distribute legitimate remote monitoring software reached 46 countries, with the US accounting for about 45% of observed activity.
- ANY.RUN said the campaign, first linked to Canadian targeting through CRA tax forms, was part of a wider operation spanning 46 countries.
- The firm said about 45% of observed activity was in the United States and that it linked 601 cases to the operation.
- Researchers said the attackers used fake documents to persuade victims to install legitimate remote monitoring and management software.
- ANY.RUN said it identified 425 kit URLs across 240 hosts, and 94% of them were seen for only one day.
ANY.RUN said the campaign first appeared to target Canada because it used Canada Revenue Agency tax forms, but its research linked the operation to 46 countries. It said the United States accounted for about 45% of observed activity and that it connected 601 cases to the wider campaign.
The attackers used fake documents to get victims to install legitimate remote monitoring and management software, according to ANY.RUN. The lures changed by target and included shipping and UPS messages, Adobe PDFs, tax notices, US Social Security Administration themes and invoices.
Researchers identified 425 kit URLs across 240 hosts, and they said 94% were seen for only a single day. ANY.RUN said the infrastructure changed faster than the attack pattern and that the operation used Vercel, GitHub Pages, Netlify and compromised websites for delivery.
Payloads were also staged through Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox and GoFile, according to the report. ANY.RUN said shared assets and a repeated delivery sequence tied separate infrastructure to the same campaign, and it said education, technology, government, banking, finance and manufacturing were among the targeted sectors.
Named in this story
Companies
- ANY.RUN
- said its researchers analysed the campaign
- Vercel
- was used for delivery infrastructure
- Netlify
- was used for delivery infrastructure
- GitHub
- was used to stage payloads
- Dropbox
- was used to stage payloads
- GoFile
- was used to stage payloads
- UPS
- had communications mimicked in the lures
- Adobe
- had PDFs used in the lures
Governments and agencies
- Canada Revenue Agency
- had tax forms used as the initial lure
- US Social Security Administration
- had themes used in the lures
Products and systems
- GitHub Pages
- was used for delivery infrastructure
- Amazon S3
- was used to stage payloads
- Cloudflare R2
- was used to stage payloads
- DigitalOcean Spaces
- was used to stage payloads
Places
- United States
- accounted for about 45% of observed activity
- Canada
- was where the campaign was first associated with targeting
How the source tells it
The piece mixed technical reporting with vendor promotion and urgent calls to adopt the author’s tools.
- vendor boosterism product claims and repeated promotion of the publisher’s own platform
- urgency imperative language pushing SOC teams to act faster and use fuller context
- hype large campaign counts and capability claims were used as proof of value