Global phishing campaign tricks victims into installing legitimate remote-control software
Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.
- Check
- Maintain an inventory and allowlist of approved remote-management tools, block or alert on any others, and warn staff that finance and government-themed messages may push legitimate remote-access software.
- Affected
- Organizations and users targeted by business-themed phishing that delivers legitimate remote monitoring and management tools; once installed, attackers gain hands-on remote access that looks like ordinary IT activity and evades reputation-based defenses.
- Fix
- Allowlist approved remote-access software and disable the rest, require remote access through controlled paths like VPNs, monitor for unexpected remote-management execution, and detect on the stable delivery chain rather than disposable domains.