US accounts for 45% of RMM phishing campaign activity

US becomes the principal target in a global RMM phishing operation
ANY.RUN has linked 601 cases to a phishing campaign operating across 46 countries, with the United States accounting for around 45% of observed activity. The operation tricks recipients into installing legitimate remote monitoring and management (RMM) software, turning a normally valid administrative tool into a vehicle for unauthorised remote access.
The campaign was initially associated with Canada because some lures imitated Canada Revenue Agency tax forms. Further analysis showed a wider, adaptable operation. Its messages and fake documents have used shipping and UPS communications, Adobe PDF themes, tax notices, US Social Security Administration themes, invoices and other pretexts tailored to prospective victims.
Infrastructure changes daily while the delivery chain persists
Researchers identified 425 phishing-kit URLs across 240 hosts. Of those hosts, 94% were observed for only a single day. The rapid turnover makes domain reputation and isolated indicators of compromise less dependable for identifying the operation over time.
Vercel was among the delivery platforms used, alongside GitHub Pages, Netlify, compromised websites and other infrastructure. Payloads were staged through Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox and GoFile. The infrastructure changes more quickly than the attack pattern, allowing the operators to discard individual domains and RMM products without abandoning the broader chain.
ANY.RUN nevertheless found persistent fingerprints that tied the infrastructure together. These included the shared font1.woff2 file, recurring image resources, and a delivery sequence in which secure.html leads to project/*.zip. The researchers also highlighted the fmtt / font1.woff2 indicator and the icons8-microsoft-word-94.png asset as useful stable signals.
Detection needs to follow behaviour, not just product names
Education, technology and government were among the most targeted industries, with banking, finance and manufacturing also prominently represented. The campaign illustrates the difficulty of distinguishing sanctioned RMM use from abuse when attackers can swap legitimate vendors and host delivery content on widely used services.
ANY.RUN advises SOC teams to build product-agnostic controls, retain focus on the delivery chain and investigate unauthorised remote-access activity. Mail-layer protections and user awareness should also account for password-protected archive delivery. The practical business implication is that teams should correlate persistent kit artefacts, browser and download behaviour, scripts, processes and network activity instead of treating a clean software reputation or a newly registered domain as sufficient evidence of safety.

