216.73.217.98

Spam campaign targeting Brazil abuses Remote Monitoring and Management tools

· Published 08/05/2025 15:13 · Modified 08/05/2025 18:46

Export JSON

Essential information

Published
08/05/2025 15:13
Modified
08/05/2025 18:46
Tags
2025-05-08 dropbox initial access broker n-able nf-e pdq connect rmm screen connect spam
Related entities
26 observables, 9 techniques (mitre), 3 others

Description

A campaign targeting Brazilian users, particularly C-level executives and financial/HR accounts, has been identified since January 2025. The campaign exploits commercial remote monitoring and management () tools, specifically and remote access tools. Attackers use Brazilian electronic invoice system () as bait, leading victims to malicious content on . The threat actor, likely an , abuses free trial periods of tools to gain complete control of target machines. The campaign's objective is to create a network of compromised machines for potential sale to third parties, including ransomware operators and state-sponsored actors. The abuse of commercial tools is increasing due to their digital signatures, full backdoor capabilities, and low cost.

External references