Threat Insight: Cybercriminals Abusing Vercel to Deliver Remote Access Malware
A phishing campaign has been identified that exploits Vercel, a legitimate frontend hosting platform, to distribute a malicious version of LogMeIn. Cybercriminals send phishing emails with links to a malicious page on Vercel, impersonating an Adobe PDF viewer and prompting users to download a disguised executable. Once executed, the malware installs and connects to a LogMeIn server, allowing remote access and control of the compromised machine. Over 28 distinct campaigns targeting more than 1,271 users have been observed in the past two months. The technique's effectiveness stems from the use of a legitimate platform, a genuine remote access tool, and social engineering tactics. Recommendations include monitoring suspicious Vercel subdomains, educating employees about fake support scams, and implementing strict controls for remote access software installations.
Pulse ID: 6855b5cc908313a5fb032505
Pulse Link: https://otx.alienvault.com/pulse/6855b5cc908313a5fb032505
Pulse Author: AlienVault
Created: 2025-06-20 19:26:04
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Adobe #CyberSecurity #Email #ICS #InfoSec #Mac #Malware #OTX #OpenThreatExchange #PDF #Phishing #RCE #SocialEngineering #bot #AlienVault