A massive phishing campaign targeting Remote Monitoring and Management (RMM) software has put 46 countries in its sights, with the United States emerging as the top target. The scheme exploits vulnerabilities in RMM tools used by managed service providers (MSPs), allowing attackers to gain access to sensitive business data and potentially even take control of entire networks.
The campaign’s success can be attributed to a clever tactic: hackers are using stolen login credentials from RMM platforms to phish users into revealing their own privileged account information. This “identity exposure” creates an active attack path, as the attackers can then use these stolen credentials to move laterally within a network, essentially unlocking a breach route at key choke points.
At its core, this campaign is about exploiting trust relationships between MSPs and their clients. RMM software allows MSPs to remotely monitor and manage client networks, making it easier for them to provide IT services. However, when an attacker gains access to an MSP’s login credentials, they can use that access to phish users into revealing their own privileged account information – the holy grail of hacking.
The scope of this campaign is staggering: with 46 countries affected and the US at the top of the list, it’s clear that no organization is immune from this type of attack. The attackers’ modus operandi suggests a high level of sophistication, using advanced social engineering techniques to trick users into divulging sensitive information.
What’s particularly concerning about this campaign is its ability to create long-term access to a network. Once an attacker has gained privileged account information, they can move freely within the network, using that access to install malware or exfiltrate data. This creates a ticking time bomb for organizations, who may not even realize they’ve been compromised until it’s too late.
As we’ve seen with this campaign, the security community is repeatedly reminded of the importance of identity management and the need to secure privileged accounts. It’s clear that attackers are targeting these vulnerabilities with increasing success, making it essential for organizations to review their own identity exposure risks and take proactive steps to mitigate them.
So what can you do? First and foremost, it’s crucial to understand how RMM software works and where potential vulnerabilities lie. Next, educate your users on the dangers of phishing attacks and the importance of strong password management practices. Finally, consider conducting a thorough risk assessment to identify any potential weaknesses in your identity management policies – before an attacker can exploit them.
Source: The Hacker News — 2026-09-03