AI Weekly Malaysia

Back to items Summaries

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

ID
21054
Status
summarized
Published
03 Sep 2026, 7:58 PM
Fetched
03 Sep 2026, 9:28 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
03 Sep 2026, 9:31 PM
Tags
Audience
developerssaas_founders

What happened

An RMM phishing campaign spanning 46 countries uses fake documents (tax forms, shipping notices, invoices) to trick victims into installing legitimate remote monitoring software. ANY.RUN linked 601 cases to the operation, with 45% targeting the US, and found 425 kit URLs across 240 hosts — 94% live for only a single day — hosted on Vercel, GitHub Pages, Netlify, and compromised sites, with payloads staged via Amazon S3, Cloudflare R2, Dropbox, and others.

Why it matters

If you deploy on Vercel, Netlify, or GitHub Pages, be aware these platforms are actively abused for disposable phishing infrastructure — your own deployments could be caught in broad takedowns or reputation blocks. No specific action is required for most builders, but SOC-adjacent teams should note that detection by individual IOC or domain reputation fails here because 94% of hosts rotate daily; shared fingerprints like font1.woff2 and the secure.html → project/*.zip delivery structure are more reliable signals.

Discussion angle

How disposable Vercel/Netlify/GitHub Pages deployments are becoming a preferred phishing delivery channel — and whether platform-level abuse detection will eventually tighten verification for all builders deploying there.

Top