RMM Tools Used In Attacks

Overview

A global phishing campaign is exploiting legitimate remote monitoring and management (RMM) tools to gain direct control of victim systems. Instead of delivering obvious malware, attackers trick users into installing signed remote‑support software that blends into normal IT activity. Analysts at ANY.RUN have tracked the campaign across 46 countries, with the United States accounting for nearly half of observed activity.

Attack Chain

  • Phishing lures: Fake tax forms, invoices, shipping notices, and shared‑file prompts.
  • Short‑lived hosting: Pages hosted on trusted cloud platforms or compromised sites, often active for only a day.
  • Password‑protected archives: ZIP files harder for automated scanners to inspect.
  • Script execution: Visual Basic scripts trigger PowerShell to fetch RMM installers.
  • Legitimate RMM payloads: GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian configured for attacker access.

Evasion Techniques

  • Signed software: Appears as normal administrative activity.
  • Rapid infrastructure churn: 425 kit URLs across 240 hosts, with 94% active for only one day.
  • Human‑like flow: hCaptcha challenges, harmless PDFs, and short delays to distract victims and evade automated analysis.
  • Telegram filtering: Visitor details sent to attacker channels for targeting.

Why It’s Dangerous

  • Hands‑on access: Attackers can browse systems, run commands, and stage deeper intrusions.
  • Valid signatures: Security products may not flag legitimate RMM installers.
  • Global reach: Targets across education, government, banking, manufacturing, and technology sectors.

Defensive Guidance

Organizations should:

  • Inventory approved RMM tools: Investigate any installation outside the allowlist.
  • Flag unexpected RMM installs: Treat them as alerts, especially after downloads from new hosting pages.
  • Train staff: Cover access‑code pages and password‑protected ZIP files.
  • Hunt recurring components: Focus on kit patterns and PowerShell downloads of MSI files.
  • Verify requests: Employees should confirm tax, invoice, or document notices through trusted channels.

Indicators of Compromise (IoCs)

  • Detection patterns: */secure.html on *.vercel[.]app, password‑protected ZIPs.
  • Domains: fillingconfirmation[.]vercel[.]app, sharedconfirmationslip[.]vercel[.]app, officialsummarybycra[.]vercel[.]app.
  • Dynamic DNS hosts: 54511[.]ddnsking[.]com, 67pon[.]swoop2[.]me.
  • Payload URLs: commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msi.
  • Hashes: 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead.

Expert in the Cloud Insight

This campaign underscores how attackers weaponize trust in legitimate IT tools. By disguising RMM installers as routine support software, they bypass traditional malware detection and gain direct remote access. The lesson is clear: verification, allowlists, and monitoring execution paths are critical defenses against phishing campaigns that exploit trusted platforms.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.