New Phishing Attack Exploits Vercel to Host and Deliver Remote Access Malware
ID: 7a4a1a2a-7b3c-5dbf-a41c-084e7663bee0
STIX ID: report--7a4a1a2a-7b3c-5dbf-a41c-084e7663bee0
Feed Name: GBHackers
Threat Score
This report details an active phishing campaign (observed since at least June 2025) that leverages trusted hosting (vercel.app and surge.sh) and browser fingerprinting to selectively serve pages that prompt targets to download signed GoTo Resolve installers; the legitimate remote-support tool is abused as a stealthy backdoor, with Telegram used for gating and multiple vercel.app subdomains and associated domains listed as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
