惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
V
Vulnerabilities – Threatpost
GbyAI
GbyAI
P
Proofpoint News Feed
L
LINUX DO - 热门话题
P
Palo Alto Networks Blog
A
About on SuperTechFans
T
Tenable Blog
M
MIT News - Artificial intelligence
IT之家
IT之家
I
Intezer
D
DataBreaches.Net
爱范儿
爱范儿
T
Threatpost
C
CERT Recently Published Vulnerability Notes
云风的 BLOG
云风的 BLOG
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
K
Kaspersky official blog
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
Y
Y Combinator Blog
Cyberwarzone
Cyberwarzone
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
Spread Privacy
Spread Privacy
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
AWS News Blog
AWS News Blog
博客园 - 聂微东
C
Check Point Blog
S
Securelist
有赞技术团队
有赞技术团队
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
D
Docker
G
GRAHAM CLULEY
T
The Exploit Database - CXSecurity.com
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tailwind CSS Blog
L
Lohrmann on Cybersecurity
G
Google Developers Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
L
LangChain Blog

Cyber Security News

BugHunter - Bug Bounty Toolkit Powered by Claude and Free AI Providers Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication Anthropic Fable 5 and Mythos 5 Access Blocked to All Users Following Government Directive Fancy Bear Hackers Abuse EdgeRouters and Cloud Services to Launch Stealthy Cyberattacks Malicious npm Campaign Steals SSH Keys, API Tokens, Cloud Credentials, and Wallet Secrets Hackers Use OnyxC2 Malware-as-a-Service to Steal Credentials From 210 Applications Facebook and Instagram Down Globally, Users Reporting Multiple Issues Google Sues Chinese Cybercrime Network for Using Gemini AI to Launch Cyberattacks 400+ Arch Linux AUR Packages Compromised in a Supply Chain Attack Deploying Infostealers Critical Vulnerability Chain in LangGraph Allows Attackers to Gain Full Server Control SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations Authorities Dismantle Cryptocurrency Laundering Services ‘AudiA6’ Used by Ransomware Gangs Hackers Use Free Spotify Premium Hacks on TikTok and Instagram to Spread Vidar Infostealer Solana FakeFix Campaign Uses 25 Malicious npm and PyPI Packages to Steal Developer Secrets Microsoft Outlook and Word Vulnerabilities Allow Attackers to Execute Malicious Code Palo Alto PAN-OS Vulnerability Allows Attackers to Execute Arbitrary Commands as Root User Google Patches 28 Chrome Vulnerabilities that Allow Attackers to Execute Malicious Code Microsoft Teams for Android Vulnerability Allows Attackers to Disclose Sensitive Data Oracle PeopleSoft 0-Day RCE Vulnerability Exploited in Attacks by ShinyHunters CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers Critical Langflow Vulnerability Exploited to Execute Malicious Code Hackers Abuse SniperDz PhaaS Ecosystem for Brand Impersonation and Browser Hijacking Researcher Hacked Google Using AI and Earned $500,000 Bug Bounty GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems Hackers Abuse Residential Proxy Networks to Hide Malicious Activity and Evade Detection Cybercriminals Abuse Chinese-Language Guarantee Marketplaces to Trade Stolen Credentials Ivanti Command Injection Vulnerability Exploited in Attacks Following PoC Release PoC Exploit Released for Guest-to-Host Escape Linux Kernel Vulnerability Oracle Emergency Security Update to Fix Critical RCE Vulnerability GreatXML BitLocker Bypass 0-Day Exploited Via Windows Defender Offline Scan Hackers Abuse VMware-Signed Binary to Sideload NIGHTFORGE Loader in Espionage Attacks Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script Hackers Abuse AWS CloudTrail and Google Cloud Logging to Evade Detection and Exfiltrate Logs China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation CISA Warns of SolarWinds Serv-U Vulnerability Exploited in Attacks Top 5 Best Tools for Simulated DDoS Attacks in 2026 Critical Vulnerability in Hugging Face Transformers Enables Remote Code Execution Attacks OWASP CVE Lite CLI - New Tool to Scan for Vulnerabilities in Your Projects Anthropic's Claude Services Down — claude.ai, Claude Code, and Cowork Affected [Updated] Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware New Magecart Attack Turns Stripe into a Malware Command Server Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation Microsoft 365 Service Degradation Bypassed Windows Driver Auto-Update Controls New SHub Stealer Variant Malware Targets Chrome, Firefox, Brave, Edge, Opera, and Crypto Wallets Malicious Browser Add-Ons Target ChatGPT, Claude, Copilot, Gemini, and DeepSeek Users
Hackers Abuse Legitimate NinjaOne RMM Software to Bypass Traditional Malware Detection
Tushar Subhra Dutta · 2026-06-13 · via Cyber Security News

A newly documented phishing campaign is using a legitimate remote management tool to silently take over victims’ computers, without deploying a single line of traditional malware.

Researchers have uncovered an active operation targeting Brazilian organizations, where attackers trick employees into installing a real enterprise software agent that then hands full remote control to the threat actors.

The campaign starts with a phishing email that looks completely routine. The link redirects the victim through a Google-based relay before landing on a fake business portal in Portuguese.

The site mimics document-access workflows that finance, procurement, and administrative employees handle every day, making it easy for targets to let their guard down.

What makes this attack particularly dangerous is what happens after the user clicks download. Instead of receiving a business document, the victim unknowingly installs a legitimate NinjaOne Remote Monitoring and Management (RMM) agent configured to connect back to attacker-controlled infrastructure.

Analysts at Cato CTRL, the threat research division of Cato Networks, identified this previously undocumented abuse chain and shared their findings in a report with Cyber Security News (CSN).

The campaign targeted at least one organization in the chemicals and advanced materials sector. The social engineering themes used, including fake fiscal records, supplier documents, and complaint-management portals, are broadly relevant across industries.

Attackers crafted phishing pages to reflect Brazilian business culture, using trusted local brand names and government service references to make the lure feel authentic.

Portions of the phishing infrastructure were still accessible as of June 3, 2026, even after responsible disclosure was made. The attackers invested significant effort in keeping researchers out and real victims in, making this a well-planned operation rather than an opportunistic one.

Hackers Abuse Legitimate NinjaOne RMM Software

Once a victim installs the NinjaOne agent, the attacker gains the same level of access a legitimate IT administrator would have over that endpoint.

This includes monitoring device activity, running remote commands, transferring files, deploying tools, and automating tasks, all through a trusted, digitally signed platform.

Since the the software is real and common in enterprise environments, most security tools do not flag it.

The downloaded file was named NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64, keeping the fiscal-document illusion alive right up to installation.

NinjaOne installer disguised as a fiscal documentNinjaOne installer disguised as a fiscal document (Source - CATO)
NinjaOne installer disguised as a fiscal documentNinjaOne installer disguised as a fiscal document (Source – CATO)

Victims are often contacted by phone and told to install what appears to be software required to access their document. This operator-guided method removes the need for exploits entirely and puts social engineering at the heart of the attack.

Anti-Analysis Infrastructure That Keeps Defenders Out

The phishing infrastructure is more sophisticated than it first appears. The pages use browser fingerprinting, sandbox detection, and geofencing to screen out researchers before delivering the payload.

During testing, the installer was only served to visitors from Brazilian IP addresses, sharply limiting visibility for anyone investigating from outside the region.

Payload delivery restricted to visitors originating from Brazil (Source - CATO)
Payload delivery restricted to visitors originating from Brazil (Source – CATO)

Embedded JavaScript tracked mouse movements, touch interactions, and scrolling behavior to confirm a real human was present.

Developer comments written in Portuguese, such as “Bot preencheu o honeypot” meaning “The bot filled the honeypot,” revealed deliberate efforts to block analysis systems.

Once checks passed, the payload was silently delivered through a hidden iframe, and traces of the mechanism were cleaned up roughly 30 seconds later.

Honeypot validation logic (Source - CATO)
Honeypot validation logic (Source – CATO)

Despite these protections, researchers found an unexpected clue. Multiple attacker-controlled domains displayed the same Earth-themed wallpaper, and pivoting on that shared image filename exposed additional campaign infrastructure.

Shared wallpaper image discovered across multiple attacker-controlled domains (Source - CATO)
Shared wallpaper image discovered across multiple attacker-controlled domains (Source – CATO)

Investigators also found overlaps with infrastructure previously linked to Venon RAT, a Brazilian threat operation using Rust-based malware, though the connection stops short of definitive attribution.

Organizations should monitor for unauthorized installations of remote management software, particularly when users are asked to install software just to view a document.

Unusual requests tied to fiscal records, supplier communications, or complaint workflows should be treated with caution. Security teams are advised to alert employees in finance, procurement, and administrative roles, as they remain the most likely targets of this kind of attack.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
Domainr64[.]orgAttacker-controlled phishing infrastructure domain
Domainhairdb[.]comAttacker-controlled phishing infrastructure domain
Domainlazybearpottery[.]netAttacker-controlled phishing infrastructure domain
Domainrectalmania[.]comAttacker-controlled phishing infrastructure domain
Domainsefaz[.]servicesPhishing domain impersonating Brazilian SEFAZ tax authority
Domainreclameaqui[.]servicesPhishing domain impersonating Brazilian complaint platform Reclame Aqui
File NameNinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64NinjaOne installer disguised as a Brazilian fiscal document used to establish attacker-controlled remote access

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.