Executive Summary
A large-scale phishing operation, active since January 2026, has been identified targeting 46 countries, with approximately 45% of activity concentrated in the United States. The campaign leverages disposable Vercel infrastructure to host document-themed lures (e.g., Canadian T4 tax forms, US SSA statements, and invoices) that trick victims into installing legitimate Remote Monitoring and Management (RMM) software. While the content mentions Mirage2FA and Kratos PhaaS in the provided context, the report itself attributes the activity to a broader 'fake-document-to-RMM kit' that may be shared among multiple affiliates.
The attack chain is characterized by the use of password-protected ZIP archives and VBS scripts that trigger PowerShell to download RMM installers. Because the final payloads are legitimate, signed commercial software products—such as GoTo Resolve, LogMeIn Rescue, and ConnectWise—traditional signature-based antivirus solutions often fail to flag the activity. The operator uses Telegram for victim filtering and FingerprintJS to evade automated analysis environments.
This campaign represents a significant risk to organizations because it bypasses standard malware detection by using 'Living off the Land' techniques with trusted software. The rapid rotation of Vercel deployments (94% observed for only one day) renders domain-based blocking ineffective, requiring defenders to focus on behavioral detection of unauthorized RMM installation and unique kit artifacts.
Key Details
Threat Name
Vercel-Hosted RMM Phishing Campaign
Affects
—
Adversary
Mirage2FA Other Adversaries and Aliases: Kratos PhaaS
MITRE Techniques
Malware/Tools
GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian, HVNC
