Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Google I/O 2025: What to expect including Gemini and Android 16 updates?

Affirm has declined 13% due to weak forecasts, with skepticism about CEO bets on 0% loans

Wisconsin dad, charged with school shooting, is the latest parent accused of gun violence

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Early Access Brokers are targeting Brazilian executives via NF-E spam and legal RMM trials
Identity

Early Access Brokers are targeting Brazilian executives via NF-E spam and legal RMM trials

userBy userMay 9, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 9, 2025Ravi LakshmananMalware/Email Security

Cybersecurity researchers have been using trial versions of commercial remote monitoring and management (RMM) software since January 2025 to warn of a new campaign targeting Portuguese-speaking users in Brazil.

“Spam messages are used using NF-E, a Brazilian electronic invoice system, as a lure to tempt users to click on hyperlinks and access malicious content hosted on Dropbox,” Cisco Talos researcher Guilherme Venere said in a report Thursday.

The attack chain starts with a specially created spam email, late invoices or unpaid payment warning that claims to occur from a financial institution or mobile phone carrier to click on the Bogus Dropbox link, which refers to the RMM tool’s binary installer.

Two notable RMM tools observed are N-Able RMM remote access and PDQ connection. Allows an attacker to be able to read and write files to and from the remote file system.

In some cases, threat actors use the remote capabilities of these agents to download and install additional RMM software, such as ScreenConnect, after the initial compromise.

Based on the general recipients observed, the campaign has been found to target primarily C-level executives and financial and human resources accounts in several industries, including some educational and government agencies.

The activity is also confidently evaluated as the work of an early access broker (IAB) who is abusing free trial periods associated with various RMM programs to gain unauthorized access. N-Able has since taken steps to disable the affected test accounts.

Cybersecurity

“In recent years, the abuse of enemy commercial RMM tools has been steadily increasing,” Venere said. “These tools are usually digitally signed by recognized entities and are fully functional backdoors, making them interesting for threat actors.”

“They also cost little or no software or infrastructure, because they are all provided by trial applications.”

This development comes amid the emergence of a variety of phishing campaigns designed to avoid modern defenses, spread a wide range of malware families or gather victim qualifications.

A campaign run by a South American cybercrime group called HIVE0148 has distributed Grandoreiro Banking Trojan to users of Mexican and Costa Rica users. Campaigns employing a legal file sharing service called GetShared bypass security protections and link users with links that host malware. Campaigns that use sales order-themed lures to deliver formbook malware use campaigns using attacks from the Expression Editor (CVE-2017-11882) and use targeted organizations. A theme that unfolds a Java-based remote access trojan named Rat Rat, which can run remote commands, record keystrokes, capture screenshots, and steal sensitive data. Using encoded JavaScript in SVG files, booby trap links in PDF attachments, dynamic phishing URLs that are rendered at runtime in OneDrive host files, and archived MHT payloads in OpenXML structures, we utilize archived MHT payloads in campaigns that demonstrate campaigns like Cloudflarrearing.

“It will become increasingly difficult for attackers to continuously evolve their tactics to bypass modern email and endpoint security solutions, detect and mitigate phishing attempts,” Intezer researcher Yuval Guri said last month. “And despite advances in cybersecurity tools, many phishing campaigns are still successful in reaching users’ inboxes.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMost Americans disapprove of Trump’s treatment of universities, a new poll finds
Next Article Ukraine accuses duo of spying for Hungary | News of the Russian-Ukraine War
user
  • Website

Related Posts

Breaking: EOL system dismantled in the US using 7,000 device proxy botnet IoT

May 9, 2025

OtterCookie V4 adds VM detection and Chrome, Metamask credential theft

May 9, 2025

Do you want to deploy an AI agent? Learn to secure them before hackers attack your business

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google I/O 2025: What to expect including Gemini and Android 16 updates?

Affirm has declined 13% due to weak forecasts, with skepticism about CEO bets on 0% loans

Wisconsin dad, charged with school shooting, is the latest parent accused of gun violence

“I’ll run on you”: New FEMA Head Issues Warning to Trump Critics | Donald Trump News

Trending Posts

“I’ll run on you”: New FEMA Head Issues Warning to Trump Critics | Donald Trump News

May 9, 2025

Who are the armed groups accusing India of supporting Pakistan? |Armed Group News

May 9, 2025

The Church must bring light to the “dark night” of the world: Pope Leo of the First Mass | Religious News

May 9, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Former Northvolt CEO Peter Carlson secures funding for the company’s new AI manufacturing startup after bankruptcy

Celsius founder Alex Masski has been sentenced to 12 years in a crypto fraud that was ordered to pay $48 million

New dedicated blockchain T-Rex raises $17 million to convert the attention layer of Web3

Top tech startup funding news for today, May 8, 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.