logo

Hackers Abuse NinjaOne RMM Agent to Gain Remote Access to Brazilian Organizations

ID: d53d058f-3aa5-5f98-a623-a00311cfa2de

STIX ID: report--d53d058f-3aa5-5f98-a623-a00311cfa2de

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Mayura Kathir

...
...

An active phishing campaign targeting Brazilian organizations uses Portuguese-language business-document lures to trick victims into downloading a legitimately signed NinjaOne RMM installer configured to register with attacker-controlled management endpoints, providing persistent remote access and full RMM capabilities. The report describes delivery portals, anti-analysis techniques (geofencing, browser fingerprinting, honeypots), observed domains as IoCs, ties to previously seen Venon RAT infrastructure (tentative), and recommends endpoint allowlisting and following CISA/NSA/MS-ISAC guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.