A phishing campaign active since January 2026 has targeted victims in 46 countries—45% of observed activity involved the United States—using tax forms, Social Security notices, invoices, VAT, shipping, Adobe PDF, and shared-file lures. Victims are sent to short-lived pages hosted on services including Vercel, Netlify, Amazon S3, and DigitalOcean Spaces, or on compromised sites, then prompted to download password-protected ZIP archives. The archives use a VBS-to-PowerShell chain to retrieve signed installers for legitimate remote monitoring and management (RMM) products, giving operators interactive access without relying on conventional malware.
The operators rotate among GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian, limiting the value of product-specific blocking. Researchers identified 425 delivery-kit URLs across 240 hosts between February 5 and July 29, with 94% of hosts remaining live for only one day; stable kit artifacts included fmtt font files, font1.woff2, icons8-microsoft-word-94.png, and a secure.html-to-ZIP delivery chain. Organizations should detect and investigate unauthorized RMM deployments, particularly script-initiated PowerShell downloads of MSI installers, newly installed support software, and password-protected ZIP files delivered through phishing pages.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Between February 5 and July 29, researchers recorded 425 phishing-kit URLs across 240 hosts supporting the campaign. The infrastructure included one-use Vercel applications, compromised sites, cloud-hosting services, and dynamic-DNS hosts; 94% of observed hosts were active for only one day.
A phishing campaign began abusing legitimate remote monitoring and management software to obtain interactive remote access to victim systems. It used fake tax documents, Social Security notices, invoices, shipping messages, and other document-themed lures.
An open Apache directory on pluks.org exposed phishing kits, archives, and operator tooling used to steal credentials through Telegram-backed workflows, including an AiTM kit with an interactive victim-session console. The exposed artifacts also showed delivery of ConnectWise ScreenConnect and Faronics Deploy Agent via document-themed lures, gated victim-specific downloads, and related domains and Telegram accounts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 64 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
carlesi.vg
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourceany.run
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.