
The RMM phishing campaign in MENA is a large-scale operation targeting organizations across government, banking, education, technology, and manufacturing by tricking users into installing legitimate remote monitoring and management software, then abusing that authorized access to keep persistent control of victim machines without triggering obvious alarms. For mid-market to enterprise organizations in regulated sectors across the region, especially government, financial services, telecom, retail, and education, this is a practical security problem rather than a theoretical one: the same trusted tools used for administration can be used to support data theft, financial fraud, and long-term intrusion.
The campaign has been documented with 425 distinct phishing kit URLs across 240 hosts, hosted on a rotating infrastructure that includes Vercel, GitHub Pages, Netlify, Amazon S3, Cloudflare R2, and Digital Ocean Spaces. Ninety-four percent of URLs are observed for a single day before rotation deliberately cycling infrastructure faster than most threat intelligence feeds can blacklist it. The United States accounts for 45% of observed activity, but the campaign's documented targeting extends to government and financial sector organizations across the MENA region.
The reason this campaign is difficult to stop with traditional controls is the same reason it is difficult to detect it using legitimate tools. The phishing lure delivers legitimate software from legitimate vendors. The remote access established is through authorized commercial products. The traffic it generates looks like authorized IT management activity. This analysis examines how the campaign works, why common defenses struggle to stop it, how threat intelligence monitoring such as SHELT’s REVA improves visibility, and which defensive actions targeted MENA organizations should prioritize before the next lure reaches their users.
The attack chain is designed to pass inspection at every layer of a standard enterprise security stack, and this dual-RMM phishing campaign began in April 2025:

The campaign's infrastructure rotation strategy compounds the detection challenge. With 94% of phishing kit URLs active for only a single day, traditional reputation-based blocking cannot keep pace. By the time the URL is blacklisted, the campaign has moved to a new host. The only intelligence layer that keeps pace with rotating criminal infrastructure is one that monitors the underlying kit patterns and delivery chain signatures not individual URLs.
The documented campaign explicitly targets government organizations, using lures themed as official documents tax notices, agency communications, administrative requests that government staff encounter regularly. UAE and Saudi government digitization programs have expanded the attack surface by putting government workflows on internet-connected endpoints. A compromised endpoint inside a ministry network gives the attacker a trusted position from which to reach internal systems, escalate privileges, and maintain access through authorized-looking remote management software that IT teams may not immediately flag as suspicious.
The campaign targets financial sector organizations specifically. For Lebanese banks with correspondent relationships across Europe and the US and Nigerian financial institutions operating in a complex regulatory environment under the Central Bank of Nigeria cybersecurity framework, a single compromised endpoint at a relationship manager or compliance officer level provides the attacker with access to internal communication, account data, and the trust relationships needed for business email compromise fraud, while phishing scams in Saudi Arabia also often target digital payment users. The RMM software installed gives the attacker real-time visibility into everything on that machine, including credentials entered after installation, such as bank portal login details and two factor authentication codes, which can then be used for fraudulent transactions and direct theft of money.
Technology companies and universities across the MENA region represent high-value targets for two distinct reasons. Related campaigns often use social engineering tied to seasonal events to make lures seem more credible. In some cases, users are also sent to phishing pages through WhatsApp links, not just email-based lures. Technology organizations have access to client environments and supplier credentials that extend the attacker's reach beyond the initial victim. Educational institutions are frequently used as staging points a compromised university account provides a trusted identity from which to approach the institution's government, industry, and international research partners using the same social engineering techniques.

The campaign's design specifically targets the blind spots of perimeter security. Email security gateways evaluate attachment and link reputation this campaign uses clean links to trusted platforms. Web filters evaluate URL reputation this campaign rotates URLs daily. Endpoint security evaluates software signatures this campaign installs signed, legitimate software. Behavioral analytics are essential because this campaign uses legitimate software and leaves subtle host-based traces instead of obvious malware signatures. The detection opportunity exists before any of these layers are engaged: in the criminal infrastructure where the campaign was built.
SHELT's REVA threat intelligence service monitors the sources where phishing campaigns leave traces before they launch against targets:
Legitimate RMM software is designed to give IT administrators full remote access to a machine screen view, file access, command execution, and the ability to install or run additional software; as an RMM tool, it can also give an attacker remote support-style access that looks routine to IT staff. When an attacker installs it through a phishing lure, they have all of those same capabilities, operating through software your security tools recognize as authorized, and they may trigger Windows User Account Control prompts that the victim sees and is asked to confirm during installation or privilege escalation. The RMM vendor's own servers relay the connection, so the traffic appears to originate from a trusted commercial service. Without specific monitoring for unauthorized RMM installations, the attacker's access is invisible to standard security controls, because the downloaded file is often an exe and may require little user interaction beyond approving the prompt.
Threat intelligence feeds that operate on URL reputation and blacklisting typically have a latency of 24 to 72 hours between a URL being identified as malicious and the block being distributed to endpoints and gateways, so defenders should track ip addresses as Indicators of Compromise, not just URLs, because the hosting infrastructure rotates quickly. This campaign rotates 94% of its URLs within a single day meaning most lure URLs are retired before the blacklist update reaches your environment, and monitoring IP and related infrastructure patterns helps confirm links between short-lived phishing pages across hosts. Campaign-level intelligence identifies the underlying infrastructure patterns, kit signatures, and delivery chain characteristics is the only detection approach that keeps pace with this rotation strategy.
Yes. A REVA engagement includes a search of dark web and deep web sources for any evidence that your organization's employees, domains, or credentials, plus examples such as phishing pages, html files, and related scams discovered across external resources, have appeared in phishing campaign targeting data including historical sweeps covering the documented active period of this campaign. This adds depth to the review by helping uncover the infrastructure behind phishing scams, not just the exposed records. If your organization's staff have been targeted by RMM phishing lures in any form, REVA intelligence sources typically surface the targeting data before or alongside the compromise itself. Effective brand protection should monitor millions of online resources for spoofing domains and phishing scams targeting the organization.
Reporting obligations depend on whether a successful compromise occurred and what data was accessed. As part of the key findings, regional monitoring shows that over 1,000 rogue domains were identified in a spoofing scheme impersonating a Saudi manpower provider, a campaign appears to evolve over time, and defenders cannot rely on ad hoc review alone. Group-IB discovered 270 domains mimicking leading postal firms in the MENA region across the Middle East, adding to the reporting and monitoring burden. Organizations subject to NESA in the UAE, NCA ECC in Saudi Arabia, NDPR in Nigeria, and ISO 27001 certification standards have incident notification obligations when personal or organizational data is accessed through an unauthorized party. SHELT can assist with the determination of whether a reportable incident occurred and with the regulatory notification process as part of a REVA engagement.
.png)
© SHELT 2023 Privacy Policy | Terms & Conditions