US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
A tax-lure phishing operation deploying remote management tools has expanded well beyond Canada to 46 countries, with the US accounting for nearly half of observed infections — highlighting how RMM abuse remains a blind spot for perimeter defences.
Summary written by editorial AI · Source link below
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.
Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
Editorial Analysis
RMM tools are trusted by default in many enterprises, making this campaign vector especially dangerous for organisations that lack application-allowlisting on endpoints.
Audit which RMM tools are authorised in your environment and block unsanctioned remote-access binaries at the endpoint and network level.
A global phishing campaign abuses legitimate remote-management software to bypass security controls — review your allowed-software policies.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d