A remote monitoring and management (RMM) phishing campaign initially believed to primarily target Canadian users has now been identified as a much larger operation spanning 46 countries, according to new research from ANY.RUN. The campaign was first associated with Canada because it used Canada Revenue Agency tax forms as phishing lures. However, researchers have since connected 601 cases to the broader operation, revealing that approximately 45 percent of observed activity was directed at organizations and users in the United States, making it the campaign’s largest target. Instead of relying on traditional malware, attackers trick victims into installing legitimate remote monitoring and management software by disguising malicious downloads as trusted documents. The phishing lures are customized for different regions and industries, using themes such as shipping notifications, UPS communications, Adobe PDF files, tax notices, United States Social Security Administration messages, invoices, and other business related documents. Researchers also found that the campaign relies on rapidly changing infrastructure hosted on services such as Vercel, making detection and tracking significantly more difficult.
ANY.RUN researchers observed that while the phishing infrastructure changes almost daily, the overall attack methodology remains consistent. During the investigation, analysts identified 425 phishing kit URLs operating across 240 different hosts, with approximately 94 percent of those hosts remaining active for only a single day before being replaced. The attackers have used multiple cloud and hosting platforms including Vercel, GitHub Pages, Netlify, compromised websites, Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile to distribute malicious content. Although the infrastructure is frequently rotated, researchers discovered several recurring elements that enabled them to link apparently separate phishing sites to the same campaign. Shared files such as font1.woff2, repeated image resources, and a consistent secure.html to project ZIP file delivery structure provided valuable indicators connecting different stages of the operation. The report noted that education, technology, government, banking, finance, and manufacturing organizations are among the industries most frequently targeted by the campaign.
Researchers emphasized that the widespread use of legitimate RMM software presents a significant challenge for defenders because the tools themselves are not inherently malicious. Instead of relying solely on indicators such as domains, file hashes, or malware signatures, security teams are encouraged to analyze the complete attack chain and behavioral patterns associated with suspicious remote access activity. Since phishing domains and RMM products can be replaced quickly, analysts need to focus on more stable characteristics of the phishing kits and delivery methods. According to the report, recurring assets, password protected archive files, and predictable download structures provide stronger indicators than individual domains or internet addresses that may disappear within hours. The researchers stressed that understanding the overall behavior of the campaign is essential for distinguishing legitimate remote administration activity from malicious abuse.
The report also highlights several defensive measures for security operations center teams. Organizations are encouraged to adopt product neutral detection strategies that monitor unauthorized remote access regardless of which RMM platform is being used. Researchers recommend strengthening email security controls to identify phishing emails carrying password protected archives while also improving employee awareness of phishing techniques involving fake invoices, shipping notifications, tax forms, and document themed lures. Providing analysts with detailed behavioral context and threat intelligence can also improve detection and response capabilities by revealing browser activity, downloaded files, processes, scripts, and network communications associated with suspicious activity. According to ANY.RUN, as threat actors increasingly combine trusted software, widely used cloud services, and disposable infrastructure, organizations need broader visibility into attacker behavior to identify campaigns that can quickly shift infrastructure while maintaining the same underlying attack techniques.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.