A newly identified cyber campaign is actively targeting organizations across Brazil, leveraging legitimate Remote Monitoring and Management (RMM) tools to gain unauthorized access to internal systems. Detected in early 2025, the operation relies on phishing emails written in Portuguese to distribute maliciously configured versions of well-known IT software. Victims receive deceptive emails that appear to originate from telecom or financial service providers, often referencing overdue payments or invoices related to Brazil’s electronic invoicing platform (NF-e). These messages contain links to Dropbox-hosted executables with names like “NOTA_FISCAL_NFe_.exe” or “Boleto_NFe_.exe,” which, when run, install authentic RMM tools under false pretenses. Although the RMM software is legitimate, its misuse allows attackers to take full control of the compromised machines without raising alarms. The campaign primarily targets individuals in executive, finance, and HR roles, as well as employees within government and educational institutions. Cisco Talos researchers have attributed the abuse to tools such as PDQ Connect and N-able Remote Access. The attackers typically use free trial versions of these platforms, creating numerous accounts with disposable email addresses to maintain persistent access over time. Because these RMM applications are digitally signed and use encrypted communication with trusted vendor domains, they often evade detection by conventional security solutions. Investigators suggest that the attackers may be initial access brokers actors who infiltrate networks and sell access to other cybercriminal groups. While the current activity is centered in Brazil, experts warn that similar techniques could easily be adopted in other regions. Organizations are encouraged to enforce strict controls over RMM tool usage, monitor for anomalous remote activity, and boost user awareness around phishing threats.
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...
The FBI has issued a warning highlighting potential security and privacy risks associated with widely used mobile applications developed by Chinese companies. These applications, a...