<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Threat-Campaign on CuraSec</title><link>https://curasec.metacog.co.kr/tags/threat-campaign/</link><description>Recent content in Threat-Campaign on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 03 Sep 2026 14:58:44 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/threat-campaign/index.xml" rel="self" type="application/rss+xml"/><item><title>RMM Phishing Campaign Hits 46 Countries, US Accounts for 45% of Cases</title><link>https://curasec.metacog.co.kr/insights/2026-09-03-us-becomes-top-target-in-rmm-phishing-campaign-spanning-46-c/</link><pubDate>Thu, 03 Sep 2026 14:58:44 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-03-us-becomes-top-target-in-rmm-phishing-campaign-spanning-46-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> RMM tool abuse as a phishing payload vector is a design-level concern for teams that deploy RMM software; no specific CVE or patch is indicated, and the summary lacks enough technical detail to drive a configuration change.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The ANY.RUN dataset of 601 cases offers an opportunity to pull sandbox telemetry and build or tune detections for tax-lure phishing delivering RMM agents; prioritize hunting for unexpected RMM tool installations and outbound RMM beacons in US-based enterprise estates.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful threat-landscape context — US enterprises are the primary target of a broad RMM-based phishing operation — but no named vendor breach or regulatory trigger warrants immediate leadership action at this stage.&lt;/li>
&lt;/ul></description></item></channel></rss>