Remote Monitoring and Management (RMM) tools have become the focal point of a sprawling phishing campaign that targets organisations across 46 countries, with the United States accounting for nearly half of all observed attacks.
Security researchers at ANY.RUN identified 601 confirmed cases tied to the operation. The campaign originally appeared regionally focused, using Canada Revenue Agency tax forms as social engineering bait to trick victims into compromising their credentials. That narrow assessment proved incomplete. Analysis expanded the scope to reveal a coordinated, multinational effort with the US as its primary target, representing approximately 45% of all tracked activity.
RMM platforms like AnyDesk, ConnectWise, and TeamViewer represent high-value attack objectives. Once attackers gain credentials for these tools, they acquire direct remote access to internal networks, bypassing perimeter defenses. This grants them the ability to move laterally, deploy malware, exfiltrate data, or establish persistent backdoors for future intrusions. The appeal to threat actors is straightforward: RMM access transforms a phishing foothold into enterprise-wide compromise potential.
The campaign's phishing methodology relies on familiarity and urgency. Attackers craft emails impersonating tax authorities, payroll systems, or corporate IT departments. Canadian iterations weaponized authentic-looking CRA documents requesting immediate action on tax accounts. US victims likely received similar pretexts involving IRS matters, payroll verification, or password reset requirements. The volume of traffic from Canadian sources initially masked the broader geographic distribution of the attack infrastructure.
Researchers tracking the operation observed consistent patterns across different regional phishing waves. Email templates referenced local compliance deadlines. Credential harvesting pages mimicked official government or corporate portals. Redirect chains funneled successful captures to attacker-controlled infrastructure. The consistency suggests either a single threat group conducting parallel campaigns or coordinated operators sharing phishing kits and infrastructure.
Organizations relying on RMM platforms face compounding risk. End users struggling to distinguish legitimate tax authority communications from phishing attempts create entry points. Once credentials compromise an RMM account, defenders face visibility challenges. Legitimate remote access traffic masks unauthorized sessions. Attackers operate with the same privileges as authorized technicians, making detection dependent on behavioral anomalies rather than access pattern violations.
The 46-country scope indicates either spray-and-pray mass phishing operations or targeted reconnaissance against specific sectors. Financial institutions, accounting firms, managed service providers, and manufacturing companies operating across borders present attractive targets. A single compromised RMM session in an MSP cascades into client network exposure.
Mitigation requires layered defenses. Organizations should implement hardware security keys for RMM platform authentication, enforcing phishing resistance beyond passwords. Multi-factor authentication on RMM accounts remains essential, particularly when token-based rather than SMS-based. Email security controls detecting phishing templates and malicious redirects reduce initial compromise rates. Monitoring RMM session anomalies, including off-hours access, unusual geographic connections, or excessive file transfers, provides detection coverage for breached accounts.
The shift from single-country to 46-country operations reflects maturation in phishing infrastructure. Threat actors have adopted scalable templates and automated infrastructure that adapts to regional contexts. The US concentration signals either victim density, sector targeting, or infrastructure positioning advantages. Organizations across all affected regions should review RMM credential hygiene immediately.
