{"id":3583,"date":"2025-05-08T07:35:45","date_gmt":"2025-05-08T07:35:45","guid":{"rendered":"http:\/\/localhost\/?p=3583"},"modified":"2025-05-08T07:35:45","modified_gmt":"2025-05-08T07:35:45","slug":"spam-campaign-targeting-brazil-abuses-remote-monitoring-and-management-tools","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=3583","title":{"rendered":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools"},"content":{"rendered":"<h2>Security Update News<\/h2>\n<h3>Update Information<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Title<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">Spam campaign targeting Brazil abuses Remote Monitoring and Management tools<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Update ID<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">TALOSBLOG:DD4BF2A9C9A877FAA5C0A18D63B0D566<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Type<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">talosblog<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Published<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-05-08T10:00:43<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Last Updated<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-05-08T10:00:43<\/td>\n<\/tr>\n<\/table>\n<h3>Security Impact<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">CVSS Score<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">0.0<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Severity<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd; color: #666666; font-weight: bold;\">NONE<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Attack Vector<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\"><\/td>\n<\/tr>\n<\/table>\n<h3>Affected CVEs<\/h3>\n<div style=\" padding: 15px; border: 1px solid #ddd; margin-bottom: 20px;\">\n<ul style=\"margin: 0; padding-left: 20px;\">\n<\/ul>\n<\/div>\n<h3>Update Details<\/h3>\n<div style=\"; padding: 15px; border-left: 4px solid #4CAF50; margin-bottom: 20px;\">\n* Cisco Talos identified a spam campaign targeting Brazilian users with commercial  _remote monitoring and management_ (RMM) tools since at least January 2025. Talos observed the use of PDQ Connect and N-able remote access tools in this campaign.<br \/>  * The spam message uses the Brazilian electronic invoice system, _NF-e_, as a lure to entice users into clicking hyperlinks and accessing malicious content hosted in Dropbox.<br \/>  * Talos has observed the threat actor abusing RMM tools in order to create and distribute malicious agents to victims. They then use the remote capabilities of these agents to download and install Screen Connect after the initial compromise.<br \/>  * Talos assesses with high confidence that the threat actor is an initial access broker (IAB) abusing the free trial periods of these RMM tools.<\/p>\n<p>* * *<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/threat-spotlight.png)<\/p>\n<p>Talos recently observed a spam campaign targeting Portuguese-speaking users in Brazil with the intention of installing commercial remote monitoring and management (RMM) tools. The initial infection occurs via _specially crafted spam messages_ purporting to be from financial institutions or cell phone carriers with an overdue bill or electronic receipt of payment issued as an NF-e (see Figures 1 and 2).<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-843fa8f9-561b-4fa2-94e5-a133746471ac.png)Figure 1. Spam message purporting to be from a cell phone provider. ![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-9f63a517-f4b0-4d3f-a7c7-5195c4d7ad61.png)Figure 2. Spam message masquerading as a bill from a financial institution.<\/p>\n<p>Both messages link to a Dropbox file, which contains the malicious binary installer for the RMM tool. The file names also contain references to NF-e in their names:<\/p>\n<p>  * AGENT_NFe_<random>.exe<br \/>  * Boleto_NFe_<random>.exe<br \/>  * Eletronica_NFe_<random>.exe<br \/>  * Nf-e<random>.exe<br \/>  * NFE_<random>.exe<br \/>  * NOTA_FISCAL_NFe_<random>.exe<\/p>\n<p> _Note: <random> means the filename uses a random sequence of letters and numbers in that position._<\/p>\n<p>The victims targeted in this campaign are mostly C-level executives and financial and human resources accounts across several industries, including some educational and government institutions. This assessment is based on the most common recipients found in the messages Talos observed during this campaign.<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-5ca62d69-b812-4471-b7b5-2db93ebe6465.jpeg)Figure 3. Targeted recipients.<\/p>\n<p>## Abusing RMM tools for profit<\/p>\n<p>This campaign&#8217;s objective is to lure the victims into installing an RMM tool, which allows the threat actor to take complete control of the target machine. _N-able RMM Remote Access_ is the most common tool distributed in this campaign and is developed by N-able, Inc., previously known as SolarWinds. N-able is aware of this abuse and took action to disable the affected trial accounts. Another tool Talos observed in some cases is _PDQ Connect_, a similar RMM application. Both provide a 15-day free trial period.<\/p>\n<p>To assess whether these actors were using a trial version rather than stolen credentials to create these accounts, Talos checked samples older than 15 days and confirmed all of them returned errors that the accounts were disabled, while newer samples found in the last 15 days were all active.<\/p>\n<p>Talos also examined the email accounts used to register for the service. They all use free email services such as Gmail or Proton Mail, as well as usernames following the theme of the spam campaign, with few exceptions where the threat actors used personal accounts. These exceptions are potentially compromised accounts which are being abused by the threat actors to create additional trial accounts. Talos did not find any samples in which the registered account was issued by a private company, so we can assess with high confidence these agents were created using trial accounts instead of stolen credentials.<\/p>\n<p>_N-able is aware of this abuse and took action to disable the affected trial accounts._<\/p>\n<p>Talos found no evidence of a common post-infection behavior for the affected machines, with most machines staying infected for days before any other malicious activity was executed by the tool. However, in some cases, we observed the threat actor installing an additional RMM tool and removing all security tools from the machine a few days after the initial compromise. This is consistent with actions of initial access broker (IAB) groups.<\/p>\n<p>An IAB&#8217;s main objective is to rapidly create a network of compromised machines and then sell access to the network to third parties. Threat actors commonly use IABs when looking for specific target companies to deploy ransomware on. However, IABs have varied priorities and may sell their services to any threat actors, including state-sponsored actors. <\/p>\n<p>Adversaries&#8217; abuse of commercial RMM tools has steadily increased in recent years. These tools are of interest to threat actors because they are usually digitally signed by recognized entities and are a fully featured backdoor. They also have little to no cost in software or infrastructure, as all of this is generally provided by the trial version application. <\/p>\n<p>Talos created a trial account to test what features were available for a trial user. In the case of the N-able remote access tool, the trial version offers a full set of features only limited by the 15-day trial period. Talos was able to confirm that by using a trial account, the threat actor has full access to the machine, including remote desktop like access, remote command execution, screen streaming, keystroke capture and remote shell access.<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-470627a6-478b-4a8d-a368-c3d868f611c8.png)Figure 4. N-able management interface showing available remote access tools. ![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-f8c0e044-526f-44ef-8249-108691fa466b.png)Figure 5. Administrative shell executed on a remote machine.<\/p>\n<p>The threat actor also has access to a fully featured file manager to easily read and write files to the remote file system.<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-650ca576-c9cc-4ff0-860e-c1e8fac6ac04.png)Figure 6. N-able file manager.<\/p>\n<p>The network traffic these tools create is also disguised as regular traffic, with many tools using communication over HTTPS and connecting to resources which are part of the infrastructure provided by the application provider. For example, N-able Remote Access uses a domain associated with its management interface, hosted on Amazon Web Services (AWS):<\/p>\n<p>  * hxxps:\/\/upload1[.]am[.]remote[.]management\/<br \/>  * hxxps:\/\/upload2[.]am[.]remote[.]management\/<br \/>  * hxxps:\/\/upload3[.]am[.]remote[.]management\/<br \/>  * hxxps:\/\/upload4[.]am[.]remote[.]management\/<\/p>\n<p> _**Disclaimer** : The URLs above are part of the management infrastructure for the RMM tools described in this blog and are not controlled by the threat actor. Customers must complete an assessment before enabling block signatures for these domains._<\/p>\n<p>The domain the agent uses is the same for any customer using the tool, with only the username and API key differentiating which customer the agent belongs to, as can be seen in Figure 7. This makes it even more difficult to identify the origin of the attacks and perform threat actor attribution. <\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-3d075735-0523-4866-bf04-3cf66416d9bc.png)Figure 7. Example configuration file.<\/p>\n<p>By extracting the configuration files inside the agent installer files still available on Dropbox, we can see some email addresses follow the same theme of the spam emails, using names of finance-related users and domains, while others could be potentially compromised accounts being used to create trial accounts for N-able Remote Access.<\/p>\n<p>With these trial versions being limited only by time and providing full remote-control features with little to no cost to the threat actors, Talos expects these tools to become even more common in attacks.<\/p>\n<p>Cisco Secure Firewall Application control is able to detect the unintended usage of RMM tools in customer&#8217;s networks. Instructions on how to set up Application control can be found at _Cisco Secure Firewall documentation_.<\/p>\n<p>## Coverage<\/p>\n<p>Ways our customers can detect and block this threat are listed below.<\/p>\n<p>![Spam campaign targeting Brazil abuses Remote Monitoring and Management tools](https:\/\/blog.talosintelligence.com\/content\/images\/2025\/05\/data-src-image-b843f50a-1d2b-4f5d-8699-cd589a41dbca.png)<\/p>\n<p>Cisco Secure Endpoint (formerly AMP for Endpoints) is ideally suited to prevent the execution of the malware detailed in this post. Try Secure Endpoint for free here.<\/p>\n<p>Cisco Secure Email (formerly Cisco Email Security) can block malicious emails sent by threat actors as part of their campaign. You can try Secure Email for free here.<\/p>\n<p>Cisco Secure Firewall (formerly Next-Generation Firewall and Firepower NGFW) appliances such as Threat Defense Virtual, Adaptive Security Appliance and Meraki MX can detect malicious activity associated with this threat.<\/p>\n<p>Cisco Secure Network\/Cloud Analytics (Stealthwatch\/Stealthwatch Cloud) analyzes network traffic automatically and alerts users of potentially unwanted activity on every connected device.<\/p>\n<p>Cisco Secure Malware Analytics (Threat Grid) identifies malicious binaries and builds protection into all Cisco Secure products.<\/p>\n<p>Cisco Secure Access is a modern cloud-delivered Security Service Edge (SSE) built on Zero Trust principles. Secure Access provides seamless transparent and secure access to the internet, cloud services or private application no matter where your users work. Please contact your Cisco account representative or authorized partner if you are interested in a free trial of Cisco Secure Access.<\/p>\n<p>Umbrella, Cisco&#8217;s secure internet gateway (SIG), blocks users from connecting to malicious domains, IPs and URLs, whether users are on or off the corporate network.<\/p>\n<p>Cisco Secure Web Appliance (formerly Web Security Appliance) automatically blocks potentially dangerous sites and tests suspicious sites before users access them.<\/p>\n<p>Additional protections with context to your specific environment and threat data are available from the Firewall Management Center.<\/p>\n<p>Cisco Duo provides multi-factor authentication for users to ensure only those authorized are accessing your network.<\/p>\n<p>Open-source Snort Subscriber Rule Set customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.<\/p>\n<p>ClamAV detections are also available for this threat:<\/p>\n<p>Txt.Backdoor.NableRemoteAccessConfig-10044370-0  <br \/>Txt.Backdoor.NableRemoteAccessConfig-10044371-0   <br \/>Txt.Backdoor.NableRemoteAccessConfig-10044372-0<\/p>\n<p>## Indicators of Compromise<\/p>\n<p> _**Disclaimer** : The URLs below are part of the management infrastructure for the RMM tools described in this blog and are not controlled by the threat actor. An assessment must be done by customers before enabling block signatures for these domains._<\/p>\n<p> _IOCs for this threat can be found on our GitHub repository _ _here_ _._<\/p>\n<p>### Network IOCs<\/p>\n<p>hxxps:\/\/upload1[.]am[.]remote[.]management\/   <br \/>hxxps:\/\/upload2[.]am[.]remote[.]management\/   <br \/>hxxps:\/\/upload3[.]am[.]remote[.]management\/   <br \/>hxxps:\/\/upload4[.]am[.]remote[.]management\/   <br \/>198[.]45[.]54[.]34[.]bc[.]googleusercontent[.]com<\/p>\n<p>### RMM Installer &#8211; Hashes<\/p>\n<p>03b5c76ad07987cfa3236eae5f8a5d42cef228dda22b392c40236872b512684e   <br \/>0759b628512b4eaabc6c3118012dd29f880e77d2af2feca01127a6fcf2fbbf10   <br \/>080e29e52a87d0e0e39eca5591d7185ff024367ddaded3e3fd26d3dbdb096a39   <br \/>0de612ea433676f12731da515cb16df0f98817b45b5ebc9bbf121d0b9e59c412   <br \/>1182b8e97daf59ad5abd1cb4b514436249dd4d36b4f3589b939d053f1de8fe23   <br \/>14c1cb13ffc67b222b42095a2e9ec9476f101e3a57246a1c33912d8fe3297878   <br \/>2850a346ecb7aebee3320ed7160f21a744e38f2d1a76c54f44c892ffc5c4ab77   <br \/>4787df4eea91d9ceb9e25d9eb7373d79a0df4a5320411d7435f9a6621da2fd6b   <br \/>51fa1d7b95831a6263bf260df8044f77812c68a9b720dad7379ae96200b065dd   <br \/>527a40f5f73aeb663c7186db6e8236eec6f61fa04923cde560ebcd107911c9ff   <br \/>57a90105ad2023b76e357cf42ba01c5ca696d80a82f87b54aea58c4e0db8d683   <br \/>63cde9758f9209f15ee4068b11419fead501731b12777169d89ebb34063467ea   <br \/>79b041cedef44253fdda8a66b54bdd450605f01bbb77ea87da31450a9b4d2b63   <br \/>a2c17f5c7acb05af81d4554e5080f5ed40b10e3988e96b4d05c4ee3e6237c31a   <br \/>b53f9c2802a0846fc805c03798b36391c444ab5ea88dc2b36bffc908edc1f589   <br \/>c484d3394b32e3c7544414774c717ebc0ce4d04ca75a00e93f4fb04b9b48ecef   <br \/>ca11eb7b9341b88da855a536b0741ed3155e80fc1ab60d89600b58a4b80d63a5   <br \/>d1efebcca578357ea7af582d3860fa6c357d203e483e6be3d6f9592265f3b41c   <br \/>e2171735f02f212c90856e9259ff7abc699c3efb55eeb5b61e72e92bea96f99c   <br \/>e34b8c9798b92f6a0e2ca9853adce299b1bf425dedb29f1266254ac3a15c87cd   <br \/>ebdefa6f88e459555844d3d9c13a4d7908c272128f65a12df4fb82f1aeab139f   <br \/>f52b4d81c73520fd25a2cc9c6e0e364b57396e0bb782187caf7c1e49693bebbf   <br \/>f5efd939372f869750e6f929026b7b5d046c5dad2f6bd703ff1b2089738b4d9c   <br \/>F68ae2c1d42d1b95e3829f08a516fb1695f75679fcfe0046e3e14890460191cf   <br \/>a71e274fc3086de4c22e68ed1a58567ab63790cc47cd2e04367e843408b9a065\n<\/div>\n<p><a href=\"https:\/\/blog.talosintelligence.com\/spam-campaign-targeting-brazil-abuses-rmm-tools\/\" target=\"_blank\" style=\"display: inline-block; color: white; padding: 10px 20px; text-decoration: none; border-radius: 4px;\">View Advisory Details<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Update News Update Information Title Spam campaign targeting Brazil abuses Remote Monitoring and Management tools Update ID TALOSBLOG:DD4BF2A9C9A877FAA5C0A18D63B0D566 Type talosblog Published 2025-05-08T10:00:43 Last Updated&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,34,12,13,33,7,69,11,5],"class_list":["post-3583","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-00","tag-exploit","tag-news","tag-none","tag-security","tag-talosblog","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=3583\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Security Update News Update Information Title Spam campaign targeting Brazil abuses Remote Monitoring and Management tools Update ID TALOSBLOG:DD4BF2A9C9A877FAA5C0A18D63B0D566 Type talosblog Published 2025-05-08T10:00:43 Last Updated...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=3583\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-08T07:35:45+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools\",\"datePublished\":\"2025-05-08T07:35:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583\"},\"wordCount\":2247,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-0.0\",\"exploit\",\"news\",\"NONE\",\"Security\",\"talosblog\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=3583#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583\",\"name\":\"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-05-08T07:35:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=3583\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3583#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=3583","og_locale":"en_US","og_type":"article","og_title":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem","og_description":"Security Update News Update Information Title Spam campaign targeting Brazil abuses Remote Monitoring and Management tools Update ID TALOSBLOG:DD4BF2A9C9A877FAA5C0A18D63B0D566 Type talosblog Published 2025-05-08T10:00:43 Last Updated...","og_url":"https:\/\/zero.redgem.net\/?p=3583","og_site_name":"zero redgem","article_published_time":"2025-05-08T07:35:45+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=3583#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=3583"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools","datePublished":"2025-05-08T07:35:45+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=3583"},"wordCount":2247,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-0.0","exploit","news","NONE","Security","talosblog","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=3583#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=3583","url":"https:\/\/zero.redgem.net\/?p=3583","name":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-05-08T07:35:45+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=3583#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=3583"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=3583#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Spam campaign targeting Brazil abuses Remote Monitoring and Management tools"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/3583","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3583"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/3583\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3583"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3583"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3583"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}