Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

RMM Phishing Campaign: Malware Analysis

0
Medium
Published: 08/26/2026 (08/26/2026, 12:32:30 UTC)
Source: AlienVault OTX General

Description

A sophisticated phishing operation initially appearing to target Canadians with fake Canada Revenue Agency T4 tax documents has evolved into a global campaign spanning 46 countries, with 45% of activity concentrated in the United States. Attackers impersonate trusted organizations including the Social Security Administration, Adobe, and various tax authorities to deliver legitimate Remote Management and Monitoring software that is then abused for unauthorized remote access. The campaign employs a reusable delivery kit featuring password-protected archives, browser fingerprinting, and Telegram-based victim filtering. Infrastructure rotates rapidly across 240 hosts, predominantly using Vercel deployments that provide legitimate TLS certificates and domain reputation. The operation leverages signed commercial RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian, making signature-based detection ineffective. Activity has remained steady from January 2026 onwards, targeting ...

Technical Details

Author
AlienVault
Tlp
white
References
["https://any.run/cybersecurity-blog/us-campaign-malware-analysis"]
Adversary
null
Pulse Id
6a8edcdfbe73c1e4ce16cdf2
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaindashboarduat.paynnow.com
domaindcsi23.swoop2.me
domainssi11.letsgo2.me
domainswoop2.me
domainhiltonheadislanddeals.com
domainquavix.vu
domaincevora.vu
domainxorlira.vu
domainvoretix.icu
domainwurel.sbs
domainmornixa.cfd
domaingetdl.jorix.cyou
domainpdfmarchlitestatementsscannedforyou.gixar.sbs
domainreportstastementformarchreviewyourssaast.harnivo.cfd
domain54511.ddnsking.com
domaindxy43.ddnsking.com
domaindyb32.ddnsking.com
domain67pon.swoop2.me
domainddn3.net2me.me
domaingonzalezjaramilloabogados.com
domainmybcdc.ca
domaintaurusburgerco.com.au
domainypatellawoffice.ca
domainelectrical-sei.com
domainherculescalgarymovers.ca
domainquantechitsolutions.com
domaindocshared.org
domainletsgo2.me
domainnet2me.me
domaintogotoresolve.com
domainwww.cyberarmor.tech

Hash

ValueDescriptionCopy
hash41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41
hash132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0
hash51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42

Url

ValueDescriptionCopy
urlhttps://www.cyberarmor.tech/blog/threat-insight-cybercriminals-abusing-vercel-to-deliver-remote-access-malware

Threat ID: 6a8ee183acd9273b49e29119

Added to database: 08/26/2026, 12:52:19 UTC

Last updated: 08/26/2026, 23:08:09 UTC

Views: 56

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses