The record
Written from the 1 report below. Nothing here is unsourced.
- A large phishing campaign has targeted 46 countries, using fake documents such as tax notices, invoices, and shipping communications to trick victims into installing legitimate remote monitoring and management software.
- Research by ANY.RUN connected 601 cases to the operation, with about 45% of activity focused on the United States, making it the top target.
- The attackers rotate their hosting infrastructure very quickly, with 94% of observed hosts seen for only a single day, using services like Vercel, GitHub Pages, and Netlify.
- Education, technology, and government are among the most targeted sectors, and researchers note detection must rely on stable campaign patterns rather than individual domains.
What to watch next
- Whether the campaign expands to new countries or industries beyond those already reported
- Changes in the delivery infrastructure or phishing kit fingerprints researchers use to track it
- New lures or RMM products adopted by the attackers as domains and tools are rotated
Coverage1
1 report
English national1
All filed from India
Named United States · Canada · Amazon S3 · Cloudflare R2 · DigitalOcean Spaces · Dropbox · GitHub · GoFile · Netlify · Vercel · ANY.RUN
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
