Phishing, Network Security

Phishing campaign targets widely used RMM platforms in 46 countries

Manager Pressing REMOTE MONITORING AND MANAGEMENT

A phishing campaign that targets mainstream remote management and monitoring (RMM) platforms has been operating in 46 countries, with 45% of observed activity focused on the United States.

Research published in late August by Any.Run said the as yet unspecified attackers run their campaigns using tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices, and shipping communications to lure victims into installing legitimate RMM software.

According to the Any.Run researchers, the operation uses the cloud-based Vercel web development platform, GitHub Pages, Netlify, compromised websites, and other infrastructure for delivery. The researchers said payloads have also been staged through services such as Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.

Adrian Culley, offensive security engineer at SafeBreach, said what stands out in this campaign isn't the phishing — tax notices, shipping alerts and invoice lures are old tradecraft — it's that the payload at the end of the chain consists of legitimate, signed remote-management software rather than custom malware.

GoTo Resolve, ScreenConnect, ConnectWise and LogMeIn are business tools staff are meant to trust, which is precisely why they work,” said Culley.

Culley pointed out that's what makes this campaign hard to catch: a signature or reputation check waves the installer straight through – no credible source has named an actor behind it — but the infrastructure discipline researchers documented, 425 kit URLs across 240 hosts with 94% live for a single day, reading like a shared phishing-as-a-service kit rather than one operator's campaign.

“The question worth asking isn't whether your EDR recognizes ScreenConnect,” said Culley. “It's whether an unexpected install of it, pulled from GitHub Pages or GoFile after a phishing click, actually fires an alert. Most environments have never tested that specific path, because the tool itself is on every allow list.”

Jason Soroko, senior fellow at Sectigo, explained that broad victim set, interchangeable lures and replaceable RMM products are more consistent with a criminal access business than a focused espionage operation, though that still remains an inference.

“The attack works because it avoids a suspicious final payload,” said Soroko. “Victims install signed remote-control software, giving the attacker the same access an IT support technician would receive.”

Soroko said enterprises should treat RMM enrollment like the creation of an administrator account: teams should keep an inventory of approved products and management tenants, then block or require approval for all others.

“Alert on any new remote-control service, especially after a browser download, password-protected ZIP, VBS or PowerShell execution, or MSI installation from cloud hosting,” said Soroko. “Email and web controls should inspect links at click time because the infrastructure can vanish within a day. Detection must follow the sequence of actions, not the product name. A valid code signature or trusted hosting domain says little about whether the remote session was authorized.”

Jason Barnhizer, director of threat operations at Blackpoint Cyber, added that RMM abuse as an initial access technique isn't new to his team: it's one of the most common patterns we deal with day-to-day in the SMB and MSP space, because attackers know these tools are already trusted and often already whitelisted in the environments they're targeting.

“We see attackers consistently abuse this trusted angle to establish persistence,” said Barnhizer. “We even see...where RMMs are used to install additional RMMs for layers of persistence.”

Barnhizer added that RMM-based campaigns are hard to attribute: first, the payload is legitimate, signed software like GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, there's no malware family to fingerprint, no unique binary to reverse engineer.

Second, Barnhizer said the delivery infrastructure has been designed to be thrown away. In this campaign, 94% of the hosting infrastructure was seen for a single day only: teams can't build a durable actor profile out of infrastructure that's gone so quickly.

Finally, the RMM product itself is interchangeable as proven by this campaign which has cycled through at least five different vendors while keeping the same delivery kit underneath. So even the one distinctive artifact an investigator might normally chase such as “What tool did they use?” changes from case to case.

“What's left is the plumbing: the phishing kit's template, its file structure, its evasion tricks,” said Barnhizer. “That gets you a campaign cluster, not a named adversary.”

Barnhizer offers five concrete steps for teams in response to this threat:

  • Inventory all authorized RMM tools today: Make Step 1 conducting an inventory of all approved remote access software.
  • Put detection on the install event itself: Tied detection to whether it came from a managed deployment or an end-user action. But if possible, Block outright where possible.
  • Tighten email and web controls around the specific delivery pattern: This would include password-protected ZIPs, redirect chains through legitimate-looking but freshly created pages, and lure themes tied to invoices, shipping, and tax season.
  • Brief the workforce on the current lures: Go beyond just “phishing” in the abstract. Specificity sticks.
  • Make sure someone's watching 24/7: These campaigns move fast, a foothold that isn't caught in the first few hours can turn into lateral movement, data theft, or ransomware well before a weekly review would catch it.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.
Steve Zurier
Steve Zurier has been a freelance writer and editor for SC Media since 2012. Now, Zurier writes daily news stories and edits SC Media’s Perspectives columns. A long-time member of the tech press, Zurier lives in Columbia, MD. During off-hours, Steve moonlights as an upright bassist for jazz and klezmer bands around the Baltimore/DC area.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds