<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries]]></title><description><![CDATA[<p dir="auto">A phishing campaign exploiting remote monitoring and management (RMM) software has expanded far beyond its initial targeting, with the United States now accounting for approximately 45% of all observed activity. The operation, which researchers at ANY.RUN initially linked to Canadian victims due to its use of Canada Revenue Agency (CRA) tax documents as lures, has been identified as part of a much larger effort spanning 46 countries.</p>
<ul>
<li>The United States is the primary target, representing nearly half of the campaign's activity.</li>
<li>The campaign leverages tax-related documents to trick users into initiating malicious installations.</li>
<li>The threat actors abuse legitimate RMM tools to gain remote access to compromised systems.</li>
</ul>
<p dir="auto">According to ANY.RUN's analysis, researchers connected 601 distinct cases to this broader global operation. The technique relies on social engineering to convince victims that they are installing necessary software, when in reality they are granting the attackers remote control capabilities. This method allows the threat actors to bypass traditional security measures by using trusted administrative tools for malicious purposes.</p>
<p dir="auto">The shift in geographic focus highlights the adaptability of the threat actors, who adjusted their lures to match the target audience. While tax season remains a common vector, the success of this campaign depends on the inherent trust users place in branded documents and familiar software names.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Given that the U.S. is now the primary target, has your organization restricted or audited the use of RMM tools to prevent this type of abuse?</p>
]]></description><link>https://xploitlk.com/topic/224/us-becomes-top-target-in-rmm-phishing-campaign-spanning-46-countries</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:36:37 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/224.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 05 Sep 2026 10:30:21 GMT</pubDate><ttl>60</ttl></channel></rss>