Executive Summary
In September 2026, security researchers identified a sophisticated RMM phishing campaign spanning 46 countries, with the United States accounting for 45% of observed activity. The operation used fake documents mimicking tax forms, shipping notifications, and government communications to trick victims into installing legitimate remote monitoring and management software. Attackers leveraged rapidly rotating infrastructure on Vercel, GitHub Pages, and Netlify, with 94% of 425 identified URLs observed for only a single day. The campaign targeted education, technology, government, banking, and manufacturing sectors.
This incident highlights the growing trend of threat actors abusing legitimate cloud services and software for malicious purposes, making detection increasingly challenging through traditional IOC-based approaches.
Why This Matters Now
This campaign demonstrates how attackers are evolving beyond traditional malware to abuse legitimate services and software, requiring security teams to shift from IOC-based detection to behavioral analysis and zero trust architectures.
Attack Path Analysis
Attackers deployed a global RMM phishing campaign targeting 46 countries, with 45% focused on the US, using fake documents and rapidly rotating Vercel infrastructure to trick victims into installing legitimate RMM software. Once installed, the RMM tools provided persistent remote access for privilege escalation and lateral movement across victim networks. The campaign leveraged trusted cloud services for payload delivery and command infrastructure while potentially exfiltrating sensitive data through the established remote channels. The operation caused widespread business disruption across education, technology, government, banking, and manufacturing sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims received phishing emails with fake tax forms, shipping notices, and Adobe PDF themes containing links to rapidly rotating Vercel infrastructure hosting malicious kits that prompted installation of legitimate RMM software
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Phishing: Spearphishing Link
User Execution: Malicious Link
Valid Accounts
Remote Access Software
Acquire Infrastructure: Domains
Obtain Capabilities: Tool
Masquerading: Match Legitimate Name or Location
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – External Penetration Testing
Control ID: 11.3.1
NYDFS 23 NYCRR 500 – Training and Monitoring
Control ID: 500.14
DORA – Identification
Control ID: Article 8
CISA ZTMM 2.0 – Network Segmentation and Monitoring
Control ID: Network and Environment
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Information Transfer Policies and Procedures
Control ID: A.13.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Social engineering campaign targeting tax forms and Social Security themes poses critical risks to government RMM infrastructure and sensitive citizen data.
Higher Education/Acadamia
Educational institutions face elevated phishing risks through document-based social engineering, requiring enhanced egress security and zero trust segmentation capabilities.
Information Technology/IT
Technology sector targeted by RMM abuse campaigns exploiting legitimate remote access tools, demanding multicloud visibility and threat detection capabilities.
Financial Services
Banking and finance organizations require encrypted traffic monitoring and egress policy enforcement to counter sophisticated social engineering and data exfiltration attempts.
Sources
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countrieshttps://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.htmlVerified
- ANY.RUN Interactive Sandbox Analysis Platformhttps://any.run/Verified
- CISA Alert on Remote Monitoring and Management Software Riskshttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
- MITRE ATT&CK Technique T1566 - Phishinghttps://attack.mitre.org/techniques/T1566/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this global RMM phishing campaign by limiting lateral movement paths and controlling egress channels used for data exfiltration. The segmented network architecture could reduce the blast radius across the 46 targeted countries and multiple industry sectors.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Cloud-native visibility and policy enforcement may have flagged suspicious download patterns from rapidly rotating Vercel infrastructure and restricted access to untrusted domains hosting malicious kits
Control: Zero Trust Segmentation
Mitigation: Microsegmentation policies would likely restrict the scope of privilege escalation by limiting RMM tool access to specific network segments and preventing unauthorized administrative credential usage across workloads
Control: East-West Traffic Security
Mitigation: East-west traffic inspection and microsegmentation would likely constrain lateral movement by blocking unauthorized inter-workload communications and restricting RMM tool reach across network segments within victim organizations
Control: Multicloud Visibility & Control
Mitigation: Unified multicloud visibility may have detected anomalous communication patterns with multiple cloud storage providers and restricted RMM traffic to unauthorized cloud services across the distributed attack infrastructure
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering and data loss prevention controls would likely constrain sensitive data exfiltration by blocking unauthorized uploads to external cloud storage services and monitoring RMM traffic for data transfer anomalies
While some systems may remain compromised, the overall business impact would likely be reduced through network segmentation that limits attack propagation across critical infrastructure and contains disruption to isolated network segments
Impact at a Glance
Affected Business Functions
- Remote IT Support Operations
- Corporate Network Security
- Data Protection and Privacy Compliance
- Business Communications
Estimated downtime: 3 days
Estimated loss: N/A
Potential unauthorized remote access to corporate systems across education, technology, government, banking, finance, and manufacturing sectors. Risk of credential theft, sensitive document access, and lateral movement through compromised networks via legitimate RMM software abuse.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Firewall (ACF) with URL filtering to block access to rapidly rotating phishing infrastructure hosted on Vercel, GitHub Pages, and Netlify platforms
- • Deploy Threat Detection & Anomaly Response capabilities to baseline normal RMM usage patterns and alert on unauthorized remote access tool installations
- • Establish Egress Security & Policy Enforcement to prevent data exfiltration through cloud storage services like Amazon S3, Dropbox, and unauthorized file sharing platforms
- • Implement Zero Trust Segmentation with least privilege access controls to limit lateral movement potential once RMM tools are installed on compromised endpoints
- • Enable Multicloud Visibility & Control to detect suspicious automation patterns and repeated malformed requests across the campaign's distributed infrastructure



