PGH Networks

US Now the Top Target in a 46-Country RMM Phishing Wave

September 3, 2026· PGH Networks Team· 5 min readCybersecurity
US Now the Top Target in a 46-Country RMM Phishing Wave

What happened

A phishing campaign that researchers first pegged as a Canada-focused operation, because the early lures leaned on Canada Revenue Agency tax forms, turns out to be far bigger than that. As reported via feeds.feedburner.com in US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries, the operation reaches 46 countries, and roughly 45% of observed activity is tied to the United States. That makes American organizations the campaign's single largest target group.

The research cited in the report, from ANY.RUN, connects 601 cases to the wider operation, which centers on tricking recipients into installing remote monitoring and management (RMM) software. RMM tools are the same category of software legitimate IT teams use to administer endpoints, which is precisely why attackers like them. Details beyond that, specific RMM products named, exact lure variants now in rotation, and industry breakdowns, are worth reading in the source and verifying against your own security vendor's advisories rather than assuming; we are not going to invent specifics the reporting does not provide.

Facebook profile lock screen on a smartphone

Why this matters for Pittsburgh SMBs

If you run a 10-to-200-person firm in Western PA, this campaign is aimed at your staff, not at a Fortune 500 SOC. The play is simple: an email that looks like a tax document, invoice, or government form, a click, and a "viewer" or "support tool" that is really a legitimate remote-access agent. Because the software is signed, commercially licensed, and often allowlisted, it frequently sails past filters that would stop obvious malware. There is no exploit to patch. The vulnerability is the person at the desk and the absence of a rule that says only approved remote tools may run.

The downstream damage maps directly onto the industries we serve. For an accounting or CPA firm, a single compromised workstation during a filing crunch exposes client tax data and triggers FTC Safeguards Rule obligations around access control and incident response. For a law firm, it is privileged matter files and trust account details. For a medical practice or behavioral health group, unauthorized remote access to a machine that touches ePHI is a reportable event under HIPAA once you cannot rule out acquisition or viewing of the data, and "we think nothing was taken" is not a defense without logs. For a financial advisory practice, it is wire fraud staged from inside your own email.

Defense contractors and their suppliers along the river corridors have the sharpest edge here. Attacker-installed remote access on a system that stores or processes CUI is both an incident-reporting obligation and a direct failure of the access-control and remote-access practices your assessment depends on. Manufacturers with mixed OT and IT environments face a different flavor: a persistent remote session on an engineering workstation is a quiet path toward production disruption, and downtime on a shop floor is measured in shifts, not tickets.

One more Pittsburgh-specific wrinkle: many local SMBs run lean, with one internal generalist or none. Attackers know smaller organizations are unlikely to have application allowlisting or 24/7 monitoring, and unauthorized RMM is exactly the kind of thing that looks normal for weeks in an unmonitored environment.

What to do about it this week

  1. Inventory the remote-access tools that are actually approved. Write down the one or two RMM and remote-support products your IT provider legitimately uses, including ours, and publish that list internally. Staff cannot flag an imposter tool if nobody has told them what the real one looks like.
  2. Hunt for everything else. Have your provider query endpoints for installed remote-access agents and running services outside that approved list, then check for unexpected outbound connections to remote-support infrastructure. This is a defined task for your managed IT team, not a vague ask.
  3. Block or restrict unapproved RMM at the endpoint. Application control, blocklists for common remote-support installers, and a policy preventing standard users from installing software are the highest-value controls here. If your EDR platform supports blocking by publisher or product, ask for it to be configured this week.
  4. Brief staff on this specific lure, not phishing in general. A five-minute all-hands note: tax forms, invoices, and government notices that ask you to download a viewer or support tool are the pattern. Nobody at our firm or yours will ever email you a link to install remote-access software.
  5. Tighten email handling of installer links and archives. Verify with your provider how Microsoft 365 is currently treating links and attachments that lead to executables and installer packages, and whether Safe Links and Safe Attachments policies apply to every mailbox, including shared and executive accounts.
  6. Confirm your incident path before you need it. Who gets called, who can isolate a machine, and how fast? Write down the notification clocks that apply to you, including HIPAA breach timelines, contractual reporting for defense work, and cyber insurance notice requirements. Your vCIO should own that document.
  7. Extend the same discipline to AI tools. Staff installing unvetted "assistants" and browser add-ins is the same behavior pattern with a different label. A short acceptable-use policy, which we cover in AI advisory engagements, keeps that from becoming next quarter's incident.

How we help

PGH Networks manages endpoints, email security, and monitoring for small and mid-sized firms across Pittsburgh, which means we can inventory remote-access software, block what does not belong, and tie the evidence back to whatever framework you answer to, whether that is HIPAA, SOC 2, FTC Safeguards, or CMMC Level 2. If you are not certain what remote tools are running on your machines right now, that is the question worth answering this week.

Call us at 724.888.7007 or reach out through the contact form, and we will scope a remote-access review for your environment.

Share

Related reading

Call usBook a meeting