Security1 distinct publisher2 min readPublished
Any.Run's researchers found a phishing kit running in 46 countries whose final payload is a signed copy of ScreenConnect or GoTo Resolve, which moves the defensive question from malware signatures to which remote-access tools may execute at all.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
The only anomalous event in the whole sequence is the last one. A staff member opens a document lure, pulls an installer from a cloud bucket, and a signed MSI stands up a remote-control service that hands the operator the same access an IT support technician would receive, in the description of Sectigo senior fellow Jason Soroko [9]. Nothing earlier in that chain trips a check, because signature and reputation checks wave the installer straight through, according to SafeBreach offensive security engineer Adrian Culley [18].
The infrastructure numbers explain why indicator feeds will not carry this one. Any.Run's researchers logged 425 kit URLs across 240 hosts, with 94% of that hosting observed for a single day only [7]. That works out to 1.8 URLs per host [1], and it leaves roughly 14 hosts with any life past the first day [2]. A blocklist built from that telemetry expires before it ships, which is why Soroko puts the weight on click-time link inspection and on a sequence rather than a product name: browser download, password-protected ZIP, VBS or PowerShell execution, MSI installation from cloud hosting, then a new remote-control service appearing [11].
The geography is lopsided. Forty-six countries, 45% of observed activity in the United States [1], which leaves 55% spread across the other 45 countries, an average near 1.2% each [3].
There are two readings of who is behind it, and both are offered as inference. Culley reads the URL and host discipline as a shared phishing-as-a-service kit rather than one operator's campaign [8]. Soroko reads the broad victim set, interchangeable lures and replaceable RMM products as more consistent with a criminal access business than focused espionage, and says plainly that this remains an inference [10]. Nobody has named an actor [12].
The control is an inventory problem. Soroko's line is to treat RMM enrollment like the creation of an administrator account: keep a list of approved products and approved management tenants, then block or require approval for everything else [13]. For a shop that already runs application control with one sanctioned RMM, that is a policy line item and some exception handling. For a managed service provider running several tools across client estates, it is the whole project, and Blackpoint Cyber threat operations director Jason Barnhizer says his team already sees RMMs used to install additional RMMs for layers of persistence [15]. Finding one unapproved agent therefore sets up the next question, which is what that agent installed after it landed.
Ranked by verification strength, evidence, and original report placement.
Soroko says teams should alert on any new remote-control service, especially after a browser download, password-protected ZIP, VBS or PowerShell execution, or MSI installation from cloud hosting, and should inspect links at click time because the infrastructure can vanish within a day; detection must follow the sequence of actions, not the product name.
Soroko says enterprises should treat RMM enrollment like the creation of an administrator account, keeping an inventory of approved products and management tenants and then blocking or requiring approval for all others.
Research published in late August by Any.Run described a phishing campaign targeting mainstream remote management and monitoring (RMM) platforms operating in 46 countries, with 45% of observed activity focused on the United States.
The campaign uses tax documents, Social Security notices, invoices, Adobe PDFs, VAT notices and shipping communications as lures to get victims to install legitimate RMM software.
The payload at the end of the chain consists of legitimate, signed remote-management software rather than custom malware, according to SafeBreach offensive security engineer Adrian Culley.
RMM products named in the campaign include GoTo Resolve, ScreenConnect, ConnectWise and LogMeIn, which Culley describes as business tools staff are meant to trust.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
ANY.RUN ties 601 RMM phishing cases to one kit rotating its hosts daily1 distinct publisher
security
Medusa's patch window is negative: 500 victims, and exploits used before disclosure7 distinct publishers
build
A spec-clean 402 is not a listing: x402scan bounced the tunnel, not the JSON1 distinct publisher
build
With CRA out of React's docs, the new project default is a rendering decision1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One report, relayed once
Every hard number — 46 countries, 45% US, 425 URLs, 240 hosts, 94% single-day — comes from Any.Run and reaches us through a single SC World write-up that does not show the methodology behind any of them. What lifts this above thin sourcing is the mechanical specificity: named products, named hosting services, a named delivery sequence, and three practitioners who describe the same behaviour from different vantage points. What holds it down is that nothing has been checked twice, and the campaign's own operators remain unnamed by anyone.
Technique in routine use, harm uncounted
As attacker tradecraft this is past the novelty stage: hundreds of live URLs, five interchangeable RMM products, a global spread, and a managed-services defender calling it one of his team's most common day-to-day patterns. What is missing is the other half of adoption — how many installs succeeded. Not one victim, intrusion or ransomware outcome is quantified, so the technique's uptake is well evidenced while its consequences are not.
Counts standing in for consequences
The framing is unusually disciplined — inferences are labelled inferences, and the piece says outright that nobody has named an actor. The small stretch is quantitative sleight of hand that no one intended: '46 countries' and '425 URLs' feel like impact numbers and are actually reach numbers. Strip them out and what remains is a well-described technique of unknown yield. The headline lands about where the evidence does, one notch ahead of it.
Everyone quoted sells the fix
Follow the money and the interpretation is uniform: the underlying research is a sandbox vendor's, and all three interpreters work for companies whose products sit exactly where the recommended controls go — offensive-security validation, certificate and identity trust, and 24/7 monitoring for the SMB and MSP channel the story identifies as most exposed. 'Make sure someone's watching 24/7' is sound advice and also a service description. Sharpening the point: the four vendors whose software is the thing being installed were never asked to respond, so the only commercial interest missing from this reporting is the one with a reason to push back.
Mechanics firm, magnitude soft
We would defend the how without hesitation: a signed remote-management installer delivered off disposable developer hosting defeats reputation-based defence, and the allow-list blind spot Culley describes is real and testable in any environment this afternoon. We would not defend the how much. Scale, spread and prevalence all hang on interested parties reporting their own telemetry through a single outlet, and a second measurement could move those numbers a long way without changing the defensive lesson at all.