Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Threat Intelligence
  5. US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

Scheduled Pinned Locked Moved Threat Intelligence
1 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    A phishing campaign exploiting remote monitoring and management (RMM) software has expanded far beyond its initial targeting, with the United States now accounting for approximately 45% of all observed activity. The operation, which researchers at ANY.RUN initially linked to Canadian victims due to its use of Canada Revenue Agency (CRA) tax documents as lures, has been identified as part of a much larger effort spanning 46 countries.

    • The United States is the primary target, representing nearly half of the campaign's activity.
    • The campaign leverages tax-related documents to trick users into initiating malicious installations.
    • The threat actors abuse legitimate RMM tools to gain remote access to compromised systems.

    According to ANY.RUN's analysis, researchers connected 601 distinct cases to this broader global operation. The technique relies on social engineering to convince victims that they are installing necessary software, when in reality they are granting the attackers remote control capabilities. This method allows the threat actors to bypass traditional security measures by using trusted administrative tools for malicious purposes.

    The shift in geographic focus highlights the adaptability of the threat actors, who adjusted their lures to match the target audience. While tax season remains a common vector, the success of this campaign depends on the inherent trust users place in branded documents and familiar software names.

    Source: The Hacker News

    Given that the U.S. is now the primary target, has your organization restricted or audited the use of RMM tools to prevent this type of abuse?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World