US-First RMM Phishing Campaign Spans 46 Countries via Disposable Vercel/Netlify Infrastructure and Password-Protected VBS-to-PowerShell Delivery

US-First RMM Phishing Campaign Spans 46 Countries via (TL-2026-2308), also tracked as US-First RMM Phishing Campaign, is a high-severity phishing campaign, first published 2026-09-03. It has no confirmed attribution, affects GoTo GoTo Resolve, maps to 10 MITRE ATT&CK techniques (T1027, T1059.001, T1059.005), and is covered by 9 detection rules and 30 indicators of compromise.

Key facts for TL-2026-2308

Threat ID
TL-2026-2308
Also known as
US-First RMM Phishing Campaign, CRA/T4 RMM Phishing Kit
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
2026-09-03
Last reviewed
2026-09-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
education, technology, government administration, banking, finance, manufacturing
Target regions
North America, Global
Detection rules
9
Indicators of compromise
30

Malware and tooling in US-First RMM Phishing Campaign Spans 46 Countries via

Malware and tooling: GoTo Resolve, LogMeIn rescue, ScreenConnect

ANY.RUN research documents a broad, ongoing phishing operation that lures victims with CRA/T4 tax, SSA, Adobe PDF, invoice/VAT, and shipping-themed pages hosted on disposable free-tier infrastructure (Vercel, Netlify, GitHub Pages, compromised sites) to trick them into extracting a password-protected ZIP whose embedded VBScript launches PowerShell to download and silently install legitimate, code-signed RMM software (GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian) for hands-on-keyboard access. Across a 174-day observation window (Feb 5-Jul 29, 2026) ANY.RUN connected 601 cases spanning 46 countries and 425 phishing-kit URLs across 240 hosts, 94% of which were live for a single day, with the United States accounting for 45% of activity and education, technology, government, banking, finance, and manufacturing as the top-targeted sectors.

How US-First RMM Phishing Campaign Spans 46 Countries via works

ANY.RUN's US-First RMM Phishing Campaign research traces a delivery-kit family that abuses legitimate, code-signed remote monitoring and management (RMM) software as its final payload rather than deploying traditional malware, allowing it to evade signature- and reputation-based detection. The kit was first observed in January 2026 as a single case and grew to a steady cadence of 17-33 connected cases per month; over a 174-day tracking window (February 5 to July 29, 2026) ANY.RUN identified 425 distinct phishing-kit URLs spread across 240 hosts and 155 unique resolving IPs, with 94% of hosts (225/240) observed for only a single day and 95% (228/240) for three days or fewer, evidencing deliberate rapid infrastructure rotation to defeat blocklisting.

The delivery chain is consistent across lure themes: a phishing email links to a disposable lure page (most heavily on *.vercel.app, with smaller volumes on *.netlify.app, GitHub Pages, compromised legitimate websites, and throwaway domains on cheap TLDs such as .vu/.sbs/.cfd/.icu/.top/.one/.cyou/.shop/.online/.site, plus dynamic-DNS hosts under ddnsking.com/swoop2.me/letsgo2.me/net2me.me). The lure page masquerades as a document portal (Canada Revenue Agency T4 tax slip, US Social Security Administration notice, Adobe PDF/Flash updater prompt, invoice/VAT alert, shipping notice, or a generic shared-file/streaming invite) and redirects to a secure.html gate that displays an 'access code' and offers a password-protected project/*.zip archive. Because the archive is password-protected, it returns HTTP 200 to automated crawlers and sandboxes but remains opaque to content inspection - a deliberate anti-analysis property. A victim who extracts the archive using the on-page code runs a VBScript that uses FileSystemObject to invoke PowerShell, which after a short sleep delay (further sandbox evasion) retrieves an RMM installer MSI from rotating staging infrastructure (Amazon S3, Cloudflare R2/DigitalOcean Spaces, GitHub, gofile.io, Dropbox, or compromised/raw-IP hosts) and silently installs it, granting the operator legitimate, signed hands-on-keyboard remote access that blends into normal IT administrative activity.

Despite domain and host churn, the kit shares durable fingerprintable assets across the whole family: an 'fmtt' web font served at img/font1.woff2 (present across all 425 kit URLs and 240 hosts), a Word icon mislabeled as a PDF icon (icons8-microsoft-word-94.png, misrepresented with alt text 'PDF Icon'), the secure.html -> project/*.zip delivery structure, and FingerprintJS-based browser/IP/geolocation fingerprinting combined with hCaptcha and Telegram Bot API (api.telegram.org) callouts used to filter out automated visitors and researchers before serving the payload. Per-recipient link paths follow a slug-epoch-hex pattern (/ftx/<6-char slug>-<10-digit epoch>-<12-hex>/), and a median link is first observed within 32 minutes of generation (77% within 24 hours), consistent with links being minted per target rather than mass-distributed.

Within the family, a dedicated CRA/T4 Canadian-tax-themed arm (27 of the observed Vercel apps, peaking at 23 apps in March 2026 during Canadian tax-filing season) delivers the password-ZIP -> VBS -> PowerShell chain to a GoToResolve or LogMeInRescue (LogMeInResolve_Unattended.msi) unattended installer; sibling Adobe-PDF, SSA, and compromised-WordPress-site variants reuse the same fmtt/font1.woff2 kit fingerprint but stage ScreenConnect, ConnectWise, or ITarian installers instead. Family-wide, ANY.RUN observed 204 cases tied to ScreenConnect and 106 to ConnectWise outside the CRA/T4 arm, with GoTo Resolve dominant by network telemetry (TLS SNI/DNS to gotoresolve.com) and 46 cases directly tied to LogMeIn Rescue/Resolve (detectable via the LOGMEINRESCUE named mutex). A durable origin IP, 46.62.197[.]232 on port 7000, was observed persisting across the churn of front-end hosting.

No named threat actor or malware family has been attributed to the campaign; ANY.RUN characterizes it as either a single operator or a phishing-as-a-service kit shared across multiple operators, based on the consistency of kit assets (font, icon, delivery-chain structure) despite the diversity of RMM payloads and lure themes. Because the final payload is legitimate, vendor-signed software rather than malware, detection must focus on the delivery chain (disposable-host lure -> access-code gate -> password ZIP -> VBS -> PowerShell -> unexpected RMM MSI) and on baselining/alerting against an organization's approved RMM tool inventory, rather than on AV signatures for the RMM installers themselves.

MITRE ATT&CK techniques used in TL-2026-2308

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.002 User Execution: Malicious File

Command and Control

T1219 Remote Access Tools

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.006 Acquire Infrastructure: Web Services; T1584 Compromise Infrastructure

Affected products and versions in US-First RMM Phishing Campaign Spans 46 Countries via

  • GoTo — GoTo Resolve
  • GoTo (LogMeIn) — LogMeIn Rescue / LogMeIn Resolve
  • ConnectWise — ScreenConnect
  • ConnectWise — ConnectWise Control / Automate
  • ITarian — ITarian RMM

Remediation for US-First RMM Phishing Campaign Spans 46 Countries via

Immediate actions

  • Maintain an approved/authorized RMM software inventory (per endpoint or per business unit) and alert on installation of any RMM agent - GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian - not on that list
  • Block or flag inbound email links to disposable *.vercel.app and *.netlify.app subdomains and to newly-registered domains on cheap TLDs (.vu, .sbs, .cfd, .icu, .top, .one, .cyou, .shop, .online, .site) and dynamic-DNS providers (ddnsking.com, swoop2.me, letsgo2.me, net2me.me)
  • Alert on VBScript (.vbs) execution originating from a user-extracted, password-protected ZIP archive delivered via email or browser download
  • Alert on PowerShell processes spawned by wscript.exe/cscript.exe that download and silently install an MSI package, particularly RMM installers, from S3/DigitalOcean Spaces/gofile.io/Dropbox URLs

Workarounds

  • Enforce application allowlisting to block execution of unauthorized RMM installers even if downloaded
  • Configure mail-gateway/proxy inspection to flag pages that request a manually-entered 'access code' before releasing a password-protected archive, and to sandbox-detonate with credential/code entry emulated where feasible

Longer-term hardening

  • Deploy EDR/behavioral detection focused on the delivery-chain sequence (disposable lure page -> secure.html access-code gate -> project/*.zip -> VBS -> PowerShell -> RMM MSI) rather than relying on AV signatures for the RMM binaries themselves, since the final payload is legitimate, vendor-signed software
  • Correlate any new remote-access/RMM software installation with unusual parent-process chains, off-hours timing, or execution paths inconsistent with the organization's IT deployment tooling
  • Run recurring user-awareness training specifically covering CRA/T4 and other tax-season lures, SSA notices, Adobe PDF/Flash update prompts, invoice/VAT alerts, and shipping notices that request an out-of-band 'access code' to open a password-protected attachment

Timeline of US-First RMM Phishing Campaign Spans 46 Countries via

  • ANY.RUN traces the earliest connected case in the wider RMM-phishing kit family to a single deployment in January 2026.
  • Start of ANY.RUN's 174-day infrastructure observation window that ultimately catalogs 425 kit URLs across 240 hosts.
  • Campaign activity peaks with 23 CRA/T4 Canadian-tax-themed Vercel apps deployed to coincide with Canadian tax-filing season.
  • 20 additional one-shot Vercel apps are deployed in July 2026 as the kit continues rotating disposable front-end infrastructure.
  • ANY.RUN's 174-day observation window closes: final tally reaches 425 kit URLs across 240 hosts and 155 unique resolving IPs, with 601 connected cases across 46 countries.
  • ANY.RUN publishes a Threat Intelligence report detailing the CRA/T4-themed RMM phishing kit cluster.
  • ANY.RUN publishes its full malware-analysis writeup on the US-First RMM Phishing Campaign, including MITRE ATT&CK mapping and IOCs.
  • The Hacker News reports on the campaign, highlighting that the United States accounts for 45% of observed activity across the 46 targeted countries.

Sources cited for US-First RMM Phishing Campaign Spans 46 Countries via

More in phishing

Detection coverage for TL-2026-2308

As of 2026-09-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2308 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-2308

1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats