ZeroHour

Search: “RMM tools”

6 stories in the last 30d

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

ANY.RUN linked 601 RMM-tool phishing cases across 46 countries, with the US the top target at 45% of observed activity.

A phishing campaign that tricks victims into installing legitimate remote monitoring and management (RMM) software spans 46 countries, with around 45% of observed activity targeting the United States, according to ANY.RUN. Lures include Canada Revenue Agency tax forms, UPS shipping notices, Adobe PDF pages, Social Security Administration themes and invoices, delivered through rapidly rotated Vercel, GitHub Pages and Netlify infrastructure. Researchers identified 425 kit URLs across 240 hosts, 94% of which appeared for only a single day, while stable kit indicators such as font1.woff2 and the secure.html to project/*.zip chain tie the infrastructure together.

The Hacker News · 14d agoPhishing & fraud in the wild

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

A phishing campaign using fake Canada Revenue Agency tax documents has expanded to 46 countries, with 45% of activity targeting the US via RMM tools.

ANY.RUN analysis traced a campaign that began with fake Canada Revenue Agency (CRA) T4 tax documents and grew into a broader remote-access operation spanning 46 countries. The United States accounts for 45% of observed activity. Attackers impersonate trusted organizations and document types to trick victims into installing remote monitoring and management (RMM) tools.

ANY.RUN · 23d agoPhishing & fraud in the wild

Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs

Microsoft warns of a human-operated campaign where attackers pose as IT support in Teams to gain remote PC control and reach domain controllers.

Microsoft Threat Intelligence observed attackers abusing Microsoft Teams external collaboration to impersonate IT/helpdesk staff, persuading employees to grant screen control via Quick Assist or RMM tools. Operators deploy malicious MSI packages via silent msiexec, run encrypted JavaScript implants through portable Node.js, and persist via EdgeUpdate Run keys or Startup folder entries. The Node.js backdoor uses HTTPS long-polling C2, captures screenshots, enumerates Active Directory, and moves laterally over WinRM (TCP 5985) to domain controllers and certificate authorities. Initial access maps to MITRE ATT&CK T1566.003 (Spearphishing via Service); no Teams vulnerability is exploited.

GBHackers · 9d agoPhishing & fraud in the wild1

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CloudSEK researchers found the BigBear 2.0 PhaaS kit, built on Evilginx2, has stolen over 5,100 Microsoft 365 credentials across 461 organizations in 40+ countries.

CloudSEK gained admin access to the BigBear 2.0 phishing-as-a-service panel, an Evilginx2-based adversary-in-the-middle platform operated by someone using the alias 'General Boss'. The team observed 3,331 unique victim IPs across more than 40 countries, 42 VPS nodes mostly on Vultr, and 5,137 credential records across 461 organizations, including 4,148 session cookies, 1,032 plaintext passwords, and 474 completed MFA-bypassed authentications. IT and managed service providers were the most targeted sector, raising supply-chain risk since their compromise can expose client infrastructure and privileged Azure AD access.

Infosecurity Magazine · 9d agoPhishing & fraud in the wild

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Phishing emails with browser-in-the-browser fake Adobe pages trick users into installing rogue ScreenConnect clients granting persistent remote access.

Huntress SOC investigated two August incidents where phishing links led to fake CAPTCHA checks and Adobe PDF Reader lures rendered as browser-in-the-browser (BiTB) pages spoofing legitimate domains like get.adobe.com. Victims downloaded what they believed was Acrobat Reader but actually installed ScreenConnect.ClientSetup.exe from attacker infrastructure, yielding two rogue ScreenConnect clients with service-based persistence. The attacker used cmd.exe and curl to stage a second client connecting to 144.172.115.59, leveraged a ScreenConnect Trial Relay domain for stealth, and ran HideCursor.exe as a defense-evasion binary. Incident 2 arrived via AT&T Office@Hand (RingCentral), with both chains stopped before broader impact.

Huntress · 8d agoPhishing & fraud in the wild

US Finance Under Phishing Pressure: What the SOC Data Reveals?

ANY.RUN SOC telemetry shows escalating phishing campaigns against US finance, including Vercel-hosted RMM attacks abusing legitimate services.

ANY.RUN analyzed SOC telemetry data on phishing targeting the US financial sector, concluding that the scale and security impact should not be understated. The analysis highlights modern campaigns such as Vercel-hosted attacks that deliver remote monitoring and management (RMM) tools. It notes that attackers increasingly abuse legitimate services and everyday workflow tools to deliver phishing, making detection harder for SOC teams.

ANY.RUN · 22d agoPhishing & fraud in the wild