Remote Monitoring Tools Exploited in New Spam Campaign Targeting Organizations

Remote Monitoring Tools Exploited in New Spam Campaign Targeting Organizations

A new and highly advanced spam campaign has been uncovered, specifically targeting organizations in Brazil. This campaign uses legitimate Remote Monitoring and Management (RMM) tools to infiltrate corporate networks by tricking victims into installing commercial software that allows attackers to take control of their systems.

Identified in early 2025, the campaign primarily targets Portuguese-speaking individuals with deceptive emails designed to lure victims into downloading RMM tools. Once installed, the attackers gain full control over the compromised systems.

The fraudsters exploit Brazil’s electronic invoice system (NF-e) as a social engineering tactic, sending fake messages that appear to come from banks or telecom companies about overdue bills or electronic receipts. These messages contain links to files hosted on Dropbox, which, when opened, lead to RMM tool installers.

The attackers use filenames featuring references to “NFe,” such as “NOTA_FISCAL_NFe_.exe” and “Boleto_NFe_.exe,” to further bolster the illusion of authenticity.

A particularly concerning aspect of the campaign is its deliberate targeting of high-level executives and employees in finance and HR departments across various industries. Additionally, government and educational institutions have also been targeted, suggesting a well-planned and strategic approach aimed at extracting valuable financial or sensitive data.

Security researchers from Cisco Talos have identified that the threat actors are exploiting legitimate RMM tools like PDQ Connect and N-able Remote Access, formerly associated with SolarWinds. These tools, designed for IT management, are hijacked by attackers to create backdoors into corporate networks.

Analysis reveals that the campaign is likely being run by Initial Access Brokers (IABs), specialized cybercriminal groups who compromise networks and then sell that access to other threat actors, such as ransomware groups and advanced persistent threat (APT) actors.

Further evidence suggests that the attackers are taking advantage of the 15-day free trial periods of these RMM solutions, repeatedly creating new trial accounts using disposable email addresses to sustain their operations.

Infection Process and Technical Breakdown

The attack begins when targets receive seemingly legitimate financial notifications with links to Dropbox-hosted files.

A deceptive spam campaign disguised as a notification from a mobile service provider has been uncovered, with a focus on luring victims into downloading what appears to be software related to invoices. In reality, the links lead to the installation of legitimate Remote Monitoring and Management (RMM) tools, but these tools are manipulated by the attackers to gain unauthorized control over victim systems.

What makes this attack particularly dangerous is that the RMM software used is digitally signed by well-known vendors, allowing it to slip past conventional security measures without triggering alarms.

Upon further investigation into the network traffic generated by these RMM tools, security experts found that the communication seemed to blend seamlessly with regular business traffic. The tools use encrypted HTTPS connections to legitimate domains, such as “upload1.am.remote.management,” which belong to the RMM provider’s infrastructure. This makes it challenging for security systems to detect the malicious activity, as the traffic appears to be from authorized business operations rather than a suspicious source.

According to experts from Cisco Talos, this method allows the attackers to maintain a backdoor into the system without the need to develop custom malware or invest in expensive infrastructure. The legitimate nature of the RMM software effectively disguises the attack.

Once the tools are installed, the attackers gain comprehensive access to the victim’s device, including full control over remote desktops, the ability to execute commands, monitor screens, log keystrokes, and access the file system without restrictions. This level of control is akin to administrative privileges, allowing the attackers to bypass traditional security alerts that would normally flag malicious code.

Currently, this campaign is primarily targeting organizations in Brazil, but experts caution that the tactics used in this attack could be easily adapted to other regions, representing an evolving and sophisticated threat that leverages legitimate software to circumvent typical security defenses.

More Articles & Posts