Abuse of Legitimate NinjaOne RMM Agent in Fiscal-Lure Phishing Campaign Targeting Brazilian Organizations (Cato CTRL) — Threadlinqs Intelligence
As of 2026-06-14, Abuse of Legitimate NinjaOne RMM Agent in Fiscal-Lure Phishing Campaign Targeting Brazilian Organizations (Cato CTRL) is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0790 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
An active, previously undocumented phishing campaign abuses the legitimate NinjaOne RMM agent to gain hands-on-keyboard administrative access to Brazilian organizations. Victims in finance,
Cato CTRL documented a Brazil-focused social-engineering operation that weaponizes a legitimate Remote Monitoring and Management (RMM) tool rather than custom malware. The intrusion begins with routine-appearing phishing emails that redirect through Google infrastructure (bc.googleusercontent.com relay pattern) to Portuguese-language portals impersonating trusted Brazilian institutions — the SEFAZ state tax authority (via sefaz[.]services) and the Reclame Aqui consumer-complaint platform (via reclameaqui[.]services), alongside staging domains r64.org, hairdb.com, lazybearpottery.net, and rectalmania.com. The fake portals present 'secure document' / 'fiscal document' verification workflows aimed at procurement, finance, accounting, and administrative personnel who routinely handle supplier and tax paperwork. In some cases operators follow up by phone, guiding victims to install 'required software.'
The delivered file is a genuine NinjaOne RMM agent named to look like a fiscal document (e.g. NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64). Because the binary is signed, legitimate, and common in enterprise environments, most endpoint and network controls do not flag it. Once installed, the agent is configured to call back to attacker-controlled NinjaOne tenancy/infrastructure, granting the operators administrative-level capabilities native to the platform: endpoint monitoring and reconnaissance, asset inventory, remote shell / command execution, file transfer (tool upload and data exfiltration), software deployment, patch management, and scripted automation — all blending into legitimate IT operations.
The campaign is wrapped in a sophisticated anti-analysis delivery layer. Payload delivery is geofenced to Brazilian IP ranges, limiting researcher visibility. Client-side JavaScript performs sandbox/automation detection (checks for Selenium, Puppeteer, Playwright, WebDriver, PhantomJS, and Nightmare), user-presence validation (mouse movement, scrolling, and touch interaction), and honeypot validation that flags automated form-fillers with the Portuguese marker 'Bot preencheu o honeypot.' The payload is served through a hidden iframe that is removed roughly 30 seconds after execution, right-click is disabled on download elements, and artifact-cleanup logic erases traces. Researchers pivoted on a shared Earth-themed wallpaper image (depicting the Americas) displayed by multiple attacker domains to expand visibility into the broader infrastructure. Cato CTRL observed command-and-control infrastructure and visual-asset overlaps with previously documented Venon RAT activity — a Brazilian, Rust-based RAT operation — suggesting a possible operational relationship or shared infrastructure, but stopped short of definitive attribution.
Target sectors: chemicals, advanced materials, finance, procurement, accounting, administrative
Target regions: Brazil, South America
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1590, T1583, T1588, T1566, T1204, T1204, T1543, T1497, T1497, T1027