US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
- ID
- 21054
- Status
- summarized
- Published
- 03 Sep 2026, 7:58 PM
- Fetched
- 03 Sep 2026, 9:28 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 03 Sep 2026, 9:31 PM
- Tags
- Audience
- developerssaas_founders
What happened
An RMM phishing campaign spanning 46 countries uses fake documents (tax forms, shipping notices, invoices) to trick victims into installing legitimate remote monitoring software. ANY.RUN linked 601 cases to the operation, with 45% targeting the US, and found 425 kit URLs across 240 hosts — 94% live for only a single day — hosted on Vercel, GitHub Pages, Netlify, and compromised sites, with payloads staged via Amazon S3, Cloudflare R2, Dropbox, and others.
Why it matters
If you deploy on Vercel, Netlify, or GitHub Pages, be aware these platforms are actively abused for disposable phishing infrastructure — your own deployments could be caught in broad takedowns or reputation blocks. No specific action is required for most builders, but SOC-adjacent teams should note that detection by individual IOC or domain reputation fails here because 94% of hosts rotate daily; shared fingerprints like font1.woff2 and the secure.html → project/*.zip delivery structure are more reliable signals.
Discussion angle
How disposable Vercel/Netlify/GitHub Pages deployments are becoming a preferred phishing delivery channel — and whether platform-level abuse detection will eventually tighten verification for all builders deploying there.