Threats Tagged 'vercel infrastructure'
View all threats tagged with 'vercel infrastructure'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vercel infrastructure'
Click on any threat for detailed analysis and mitigation recommendations
This is a sophisticated global phishing campaign that abuses legitimate Remote Management and Monitoring (RMM) software to gain unauthorized remote access. Initially targeting Canadians with fake Canada Revenue Agency tax documents, it has expanded to 46 countries, with nearly half of the activity in the United States. Attackers impersonate trusted organizations and use advanced techniques such as password-protected archives, browser fingerprinting, and Telegram-based victim filtering. The campaign uses rapidly rotating infrastructure hosted mainly on Vercel, leveraging legitimate TLS certificates and domain reputations. Signed commercial RMM tools are abused, making traditional signature-based detection ineffective. The campaign has been active steadily since January 2026. MediumCampaign Join the discussion | AlienVault OTX General | 08/26/2026, 12:32:30 UTC Added: 08/26/2026, 12:52:19 UTC |
A threat hunting investigation identified suspicious PowerShell content served from an IP address (203.188.171.166) and domain (dorenzaa.com), both retrieving ZIP archives from Vercel-hosted infrastructure. The PowerShell loaders extract and execute payloads locally, including Grape.exe, UltraToolliteSetup.exe, and draw.io.exe. Analysis revealed heavily obfuscated PowerShell stages utilizing Base64 encoding, XOR-based obfuscation with the key 'Write', dynamically constructed IEX commands, and hidden PowerShell execution. A decoy 'Verification complete!' message disguised as Google.com was presented to victims during execution. Multiple Vercel instances hosted additional artifacts including loader scripts and executables. The initial infection vector remains unidentified, suggesting these PowerShell-hosting URLs represent second-stage delivery points in a multi-stage attack chain. Join the discussion | AlienVault OTX General | 08/10/2026, 14:20:36 UTC Added: 08/10/2026, 15:56:14 UTC |
Showing 1 to 2 of 2 results