RMM Phishing Campaign: Malware Analysis
A sophisticated phishing operation initially appearing to target Canadians with fake Canada Revenue Agency T4 tax documents has evolved into a global campaign spanning 46 countries, with 45% of activity concentrated in the United States. Attackers impersonate trusted organizations including the Social Security Administration, Adobe, and various tax authorities to deliver legitimate Remote Management and Monitoring software that is then abused for unauthorized remote access. The campaign employs a reusable delivery kit featuring password-protected archives, browser fingerprinting, and Telegram-based victim filtering. Infrastructure rotates rapidly across 240 hosts, predominantly using Vercel deployments that provide legitimate TLS certificates and domain reputation. The operation leverages signed commercial RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian, making signature-based detection ineffective. Activity has remained steady from January 2026 onwards, targeting ...
Indicators of Compromise
- domain: dashboarduat.paynnow.com
- domain: dcsi23.swoop2.me
- domain: ssi11.letsgo2.me
- domain: swoop2.me
- domain: hiltonheadislanddeals.com
- domain: quavix.vu
- domain: cevora.vu
- domain: xorlira.vu
- domain: voretix.icu
- domain: wurel.sbs
- domain: mornixa.cfd
- domain: getdl.jorix.cyou
- domain: pdfmarchlitestatementsscannedforyou.gixar.sbs
- domain: reportstastementformarchreviewyourssaast.harnivo.cfd
- domain: 54511.ddnsking.com
- domain: dxy43.ddnsking.com
- domain: dyb32.ddnsking.com
- domain: 67pon.swoop2.me
- domain: ddn3.net2me.me
- domain: gonzalezjaramilloabogados.com
- domain: mybcdc.ca
- domain: taurusburgerco.com.au
- domain: ypatellawoffice.ca
- domain: electrical-sei.com
- domain: herculescalgarymovers.ca
- domain: quantechitsolutions.com
- hash: 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41
- hash: 132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0
- hash: 51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42
- url: https://www.cyberarmor.tech/blog/threat-insight-cybercriminals-abusing-vercel-to-deliver-remote-access-malware
- domain: docshared.org
- domain: letsgo2.me
- domain: net2me.me
- domain: togotoresolve.com
- domain: www.cyberarmor.tech
RMM Phishing Campaign: Malware Analysis
Description
A sophisticated phishing operation initially appearing to target Canadians with fake Canada Revenue Agency T4 tax documents has evolved into a global campaign spanning 46 countries, with 45% of activity concentrated in the United States. Attackers impersonate trusted organizations including the Social Security Administration, Adobe, and various tax authorities to deliver legitimate Remote Management and Monitoring software that is then abused for unauthorized remote access. The campaign employs a reusable delivery kit featuring password-protected archives, browser fingerprinting, and Telegram-based victim filtering. Infrastructure rotates rapidly across 240 hosts, predominantly using Vercel deployments that provide legitimate TLS certificates and domain reputation. The operation leverages signed commercial RMM tools including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian, making signature-based detection ineffective. Activity has remained steady from January 2026 onwards, targeting ...
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://any.run/cybersecurity-blog/us-campaign-malware-analysis"]
- Adversary
- null
- Pulse Id
- 6a8edcdfbe73c1e4ce16cdf2
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaindashboarduat.paynnow.com | — | |
domaindcsi23.swoop2.me | — | |
domainssi11.letsgo2.me | — | |
domainswoop2.me | — | |
domainhiltonheadislanddeals.com | — | |
domainquavix.vu | — | |
domaincevora.vu | — | |
domainxorlira.vu | — | |
domainvoretix.icu | — | |
domainwurel.sbs | — | |
domainmornixa.cfd | — | |
domaingetdl.jorix.cyou | — | |
domainpdfmarchlitestatementsscannedforyou.gixar.sbs | — | |
domainreportstastementformarchreviewyourssaast.harnivo.cfd | — | |
domain54511.ddnsking.com | — | |
domaindxy43.ddnsking.com | — | |
domaindyb32.ddnsking.com | — | |
domain67pon.swoop2.me | — | |
domainddn3.net2me.me | — | |
domaingonzalezjaramilloabogados.com | — | |
domainmybcdc.ca | — | |
domaintaurusburgerco.com.au | — | |
domainypatellawoffice.ca | — | |
domainelectrical-sei.com | — | |
domainherculescalgarymovers.ca | — | |
domainquantechitsolutions.com | — | |
domaindocshared.org | — | |
domainletsgo2.me | — | |
domainnet2me.me | — | |
domaintogotoresolve.com | — | |
domainwww.cyberarmor.tech | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41 | — | |
hash132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0 | — | |
hash51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://www.cyberarmor.tech/blog/threat-insight-cybercriminals-abusing-vercel-to-deliver-remote-access-malware | — |
Threat ID: 6a8ee183acd9273b49e29119
Added to database: 08/26/2026, 12:52:19 UTC
Last updated: 08/26/2026, 23:08:09 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.