logo

Cato CTRL™ Threat Research: From Fiscal Lures to Remote Access, A Previously Undocumented NinjaOne RMM Abuse Chain

ID: a1fbcaca-8d93-5622-9f82-8460bdba6a12

STIX ID: report--a1fbcaca-8d93-5622-9f82-8460bdba6a12

Feed Name: Cato Networks

Threat Score
70/100

Date Published: 2026-06-10

Date Updated: 2026-07-23

Author: Tal Biran

...
...

Cato CTRL identified a Portuguese-language phishing campaign targeting Brazilian organizations that uses trusted business-document lures and Googleusercontent redirection to deliver a NinjaOne Remote Monitoring and Management agent configured for attacker-controlled remote access; the campaign includes geofencing, browser-fingerprinting, sandbox and user-interaction checks to gate payload delivery, reused frontend assets (a wallpaper) used as a pivot to expand infrastructure visibility, and several domains and MITRE ATT&CK mappings, with recommendations to monitor and block unauthorized RMM installations and related infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.