RMM phishing campaign spanning 46 countries
Campaign
Summary
Hide ▲
Show ▼
A rotating RMM phishing campaign now spans 46 countries, increasing the risk of unauthorized remote-access installation and making detection harder. The United States is the top target, accounting for about 45% of observed activity. Attackers use fake documents, including CRA tax forms, shipping notices, invoices, and Social Security themes, to push victims toward legitimate remote monitoring and management software. Rapidly changing disposable infrastructure, including Vercel, helps the operation evade tracking.
Related Happenings
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor Meta
H score62
First: 13.08.2026 21:15
Last: 13.08.2026 21:15
Sources 1
About this happening:
Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
Jewelbug pairs espionage with industrial-scale cryptocurrency fraud
Threat Actor MetaAbout this happening: Jewelbug is a China-linked threat actor operating a blended espionage and cryptocurrency fraud ecosystem. Broadcom’s Symantec and Carbon Black Threat Hunter...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
Campaign
H score39
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
GreyVibe AI-assisted cyberespionage campaign targeting Ukraine-linked organizations
CampaignAbout this happening: GreyVibe is running an AI-assisted cyberespionage campaign against Ukrainian and Ukraine-related organizations, expanding the threat to military, government, civilian,...
Triad Nexus expands fraud ecosystem and shifts into emerging markets after 2025 US sanctions
Threat Actor Meta
H score43
First: 14.04.2026 15:00
Last: 14.04.2026 15:00
Sources 1
About this happening:
Triad Nexus expanded its fraud ecosystem after US Treasury sanctions in 2025, increasing operational scale and shifting into emerging markets. The network’s use of U...
Triad Nexus expands fraud ecosystem and shifts into emerging markets after 2025 US sanctions
Threat Actor MetaAbout this happening: Triad Nexus expanded its fraud ecosystem after US Treasury sanctions in 2025, increasing operational scale and shifting into emerging markets. The network’s use of U...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
03.09.2026 14:58 2 articles · 3h ago
RMM phishing campaign spans 46 countries
Campaign Scope UpdateANY.RUN reported an RMM phishing campaign that spans 46 countries, with the United States accounting for about 45% of observed activity. Researchers connected 601 cases to the wider operation, which uses fake documents such as CRA tax forms, shipping notices, Adobe PDFs, tax notices, US Social Security Administration themes, and invoices to trick victims into installing legitimate remote monitoring and management (RMM) software. The delivery chain uses rapidly rotated disposable infrastructure including Vercel, GitHub Pages, Netlify, and compromised websites, while payloads are staged through services including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile. Shared assets such as font1.woff2, recurring image resources, and the secure.html → project/*.zip structure helped connect separate infrastructure to the same campaign.
Show sources
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries — thehackernews.com — 03.09.2026 14:58
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries — thehackernews.com — 03.09.2026 14:58