Cato CTRL™ Threat Research: From Fiscal Lures to Remote Access, A Previously Undocumented NinjaOne RMM Abuse Chain
ID: a1fbcaca-8d93-5622-9f82-8460bdba6a12
STIX ID: report--a1fbcaca-8d93-5622-9f82-8460bdba6a12
Feed Name: Cato Networks
Cato CTRL identified a Portuguese-language phishing campaign targeting Brazilian organizations that uses trusted business-document lures and Googleusercontent redirection to deliver a NinjaOne Remote Monitoring and Management agent configured for attacker-controlled remote access; the campaign includes geofencing, browser-fingerprinting, sandbox and user-interaction checks to gate payload delivery, reused frontend assets (a wallpaper) used as a pivot to expand infrastructure visibility, and several domains and MITRE ATT&CK mappings, with recommendations to monitor and block unauthorized RMM installations and related infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
