Skip to main content
Emerging Threats

US Targets 45% of Global RMM Phishing Campaign

People work at computer stations in a well-lit office interior, some looking concerned.

Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target, according to ANY.RUN research.

Scale and geography: 46 countries, 601 linked cases, US-first targeting

What began as a phishing operation that looked focused on Canada has been traced to a global effort across 46 countries. ANY.RUN connected 601 cases to the wider operation and found that roughly 45% of observed activity targeted the United States, making the U.S. the single largest recipient of this wave of attacks. Education, technology, and government sectors rank among the most-targeted industries, with banking, finance, and manufacturing also prominently present.

Delivery infrastructure: disposable hosts, trusted platforms, and daily rotation

The campaign relies on rapidly rotated, disposable infrastructure to complicate tracking. Researchers identified 425 kit URLs across 240 hosts; 94% of those hosts were observed for only a single day. The operation has used delivery platforms including Vercel, GitHub Pages, Netlify, and compromised websites, while staging payloads through services such as Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile. That mix of legitimate platforms and short-lived domains is central to how the attackers evade detection.

Lures and abuse of legitimate RMM software

Attackers use carefully tailored document-based lures to induce targets to install legitimate remote monitoring and management (RMM) software. Initial lures employed Canada Revenue Agency (CRA) tax forms, but the campaign adapts content to local contexts: shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices, and other business documents have all been observed. The operation delivers real RMM tools behind fake documents, turning legitimate remote-access products into the mechanism for compromise. The campaign also uses password-protected archives as a delivery technique that can bypass some mail filters.

Persistent fingerprints and practical detection indicators

Despite the ephemeral domains, researchers found persistent fingerprints that tie disparate infrastructure to the same campaign. Shared assets such as font1.woff2, recurring image resources like icons8-microsoft-word-94.png, and a delivery chain that follows secure.html → project/*.zip helped analysts connect otherwise separate hosts. ANY.RUN’s analysis emphasizes that individual domains and RMM product names are disposable, while the delivery chain and asset patterns are more stable — a distinction defenders should use to prioritize detection.

What this means for SOC teams, procurement leaders, and end users

  • SOC teams: Build product-agnostic defenses focused on delivery chains and unauthorized remote-access activity rather than relying solely on malware verdicts or domain reputation. Prioritize detection of kit indicators (for example, font1.woff2, icons8-microsoft-word-94.png, and the secure.html → project/*.zip chain) and account for password-protected archive delivery. Provide analysts with behavioral context — browser activity, scripts, processes, downloads, and network behavior — to distinguish legitimate RMM use from abuse.
  • Procurement and IT leaders: Recognize that legitimate RMM software can be abused and switched between vendors, creating visibility gaps. The campaign underscores the need for vendor-agnostic monitoring of remote-access tools and tighter controls around sanctioned RMM installation and use.
  • End users and defenders of mail infrastructure: Raise awareness about document-based social engineering and add mail-layer controls that flag or block password-protected archives used as carriers for installers or scripts.

ANY.RUN’s Interactive Sandbox and Threat Intelligence Lookup played a role in exposing the campaign’s browser activity, scripts, processes, downloads, and network behavior and in linking persistent indicators to related infrastructure and cases. The operational lesson is blunt: detection strategies that depend solely on individual IOCs, domain reputation, or malware verdicts will be outpaced by an adversary that blends legitimate services with disposable infrastructure.

The campaign moves quickly, but it leaves traces — stable kit assets and a repeatable delivery chain. The defenders who act fastest will be those who prioritize behavioral context, instrument their delivery chains, and operationalize the specific indicators this investigation surfaced.

Original reporting