US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
RMM phishing campaign targeting US, 45% of activity
Intelligence analysis by Qwen 2.5 (3B)

RMM phishing campaign targeting US, 45% of activity, spans 46 countries, uses fake documents to trick victims into installing RMM software.
Bad guys tricked people into installing software by pretending to be real companies. They used fake documents to trick people into giving away their passwords. The US got tricked the most.
Analysis
Attack Chain Overview by ANY.RUN
The campaign's infrastructure changes significantly faster than its attack pattern. ANY.RUN researchers identified 425 kit URLs across 240 hosts, 94% of which were observed for only a single day. The operation has used Vercel, GitHub Pages, Netlify, compromised websites, and other infrastructure for delivery. Payloads have also been staged through services including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.
Persistent Indicators
Shared assets such as font1.woff2, recurring image resources, and the secure.html → project/*.zip delivery structure helped researchers connect otherwise separate infrastructure to the same campaign.
Target Industries
Education, technology, and government are among the top targeted industries. Banking, finance, and manufacturing are also prominently present.
Key points
- RMM phishing campaign targeting US, 45% of activity
- Campaign spans 46 countries
- Uses fake documents to trick victims into installing RMM software
By understanding the attack patterns, security teams can better protect against similar threats in the future.
The rapid rotation of infrastructure makes it harder to detect and prevent these attacks.



