Hackers Abuse Legitimate RMM Tools in 46-Country Phishing Campaign for Remote Access
A sophisticated phishing campaign is exploiting legitimate remote monitoring and management (RMM) tools like GoTo Resolve and LogMeIn Rescue to gain unauthorized remote access to victim systems across 46 countries.

A widespread phishing operation is leveraging legitimate remote monitoring and management (RMM) tools to establish unauthorized remote access to victim systems. Instead of deploying traditional malware, attackers are tricking users into installing trusted RMM software, allowing them to blend in with normal IT activities and bypass security defenses. This campaign, active since January 2026, has impacted victims in 46 countries, with a significant focus on North America.
The attack chain begins with convincing lures, such as fake tax documents (like Canada Revenue Agency T4 forms), invoices, or shipping notifications, delivered via emails pointing to short-lived web pages hosted on legitimate cloud platforms or compromised websites. These pages often present a document portal, provide an access code, and offer a password-protected ZIP archive. This password protection is a tactic to evade automated email scanners.
Upon extracting the archive and executing a Visual Basic script, the payload initiates the download of a legitimate RMM installer. The campaign has been observed using tools like GoTo Resolve and LogMeIn Rescue, with related activity involving ScreenConnect, ConnectWise, and ITarian. This approach mirrors previous abuse of legitimate remote support tools, where they were reconfigured for attacker-controlled access.
Before delivering the final payload, the attackers implement several checks. These include collecting browser and location details, presenting an hCaptcha challenge, and sometimes using Telegram to filter visitors. A deliberate delay before the download and the display of a harmless PDF are employed to keep the victim engaged and to hinder automated analysis.
Researchers have identified a high rate of infrastructure churn, with 94% of observed hosts appearing for only one day, including numerous single-use applications on platforms like Vercel. This rapid rotation of disposable domains and applications makes traditional blocking strategies less effective.
Defenders are advised to treat any unexpected RMM installation as a critical alert, especially when it follows a download from a new hosting page, a password-protected archive, or a script launched by a user from an unusual context. Maintaining an approved inventory of remote-access products and investigating any installations outside this list is crucial.
To combat this threat, security teams should enhance email controls and staff awareness training to specifically address access-code pages and password-protected ZIP files. Hunting for recurring components of the delivery kit and the page-to-archive flow, rather than solely relying on disposable domains, is recommended. Correlating PowerShell activity that downloads MSI files with newly installed support software can help detect intrusions before remote control is widely exploited.
The campaign's broad targeting across sectors like education, technology, government, banking, manufacturing, and finance underscores the need for vigilance. Employees are urged to verify urgent document or invoice requests through independently known channels, rather than relying on links provided in emails.