A phishing campaign active since January 2026 uses disposable Vercel-hosted lure pages to deliver password-protected ZIP archives containing VBS scripts. The scripts launch PowerShell to download and install legitimate, signed RMM software that provides hands-on-keyboard remote access. The campaign spans 46 countries with 45% of activity in the United States and uses interchangeable RMM products, making product-specific detection ineffective. Durable detection pivots include a shared web font (font1.woff2), a mislabeled Word icon asset, and a consistent secure.html to project/*.zip download chain.
Vercel hosting
1 post
A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign