Executive Summary

In September 2026, security researchers identified a sophisticated RMM phishing campaign spanning 46 countries, with the United States accounting for 45% of observed activity. The operation used fake documents mimicking tax forms, shipping notifications, and government communications to trick victims into installing legitimate remote monitoring and management software. Attackers leveraged rapidly rotating infrastructure on Vercel, GitHub Pages, and Netlify, with 94% of 425 identified URLs observed for only a single day. The campaign targeted education, technology, government, banking, and manufacturing sectors.

This incident highlights the growing trend of threat actors abusing legitimate cloud services and software for malicious purposes, making detection increasingly challenging through traditional IOC-based approaches.

Why This Matters Now

This campaign demonstrates how attackers are evolving beyond traditional malware to abuse legitimate services and software, requiring security teams to shift from IOC-based detection to behavioral analysis and zero trust architectures.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers used rapidly rotating infrastructure with 94% of URLs active for only one day, combined with legitimate cloud services like Vercel and GitHub Pages to host their phishing kits.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this global RMM phishing campaign by limiting lateral movement paths and controlling egress channels used for data exfiltration. The segmented network architecture could reduce the blast radius across the 46 targeted countries and multiple industry sectors.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Cloud-native visibility and policy enforcement may have flagged suspicious download patterns from rapidly rotating Vercel infrastructure and restricted access to untrusted domains hosting malicious kits

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely restrict the scope of privilege escalation by limiting RMM tool access to specific network segments and preventing unauthorized administrative credential usage across workloads

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic inspection and microsegmentation would likely constrain lateral movement by blocking unauthorized inter-workload communications and restricting RMM tool reach across network segments within victim organizations

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Unified multicloud visibility may have detected anomalous communication patterns with multiple cloud storage providers and restricted RMM traffic to unauthorized cloud services across the distributed attack infrastructure

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering and data loss prevention controls would likely constrain sensitive data exfiltration by blocking unauthorized uploads to external cloud storage services and monitoring RMM traffic for data transfer anomalies

Impact (Mitigations)

While some systems may remain compromised, the overall business impact would likely be reduced through network segmentation that limits attack propagation across critical infrastructure and contains disruption to isolated network segments

Impact at a Glance

Affected Business Functions

  • Remote IT Support Operations
  • Corporate Network Security
  • Data Protection and Privacy Compliance
  • Business Communications
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential unauthorized remote access to corporate systems across education, technology, government, banking, finance, and manufacturing sectors. Risk of credential theft, sensitive document access, and lateral movement through compromised networks via legitimate RMM software abuse.

Recommended Actions

  • Implement Cloud Firewall (ACF) with URL filtering to block access to rapidly rotating phishing infrastructure hosted on Vercel, GitHub Pages, and Netlify platforms
  • Deploy Threat Detection & Anomaly Response capabilities to baseline normal RMM usage patterns and alert on unauthorized remote access tool installations
  • Establish Egress Security & Policy Enforcement to prevent data exfiltration through cloud storage services like Amazon S3, Dropbox, and unauthorized file sharing platforms
  • Implement Zero Trust Segmentation with least privilege access controls to limit lateral movement potential once RMM tools are installed on compromised endpoints
  • Enable Multicloud Visibility & Control to detect suspicious automation patterns and repeated malformed requests across the campaign's distributed infrastructure

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image