{"id":10148,"date":"2026-01-26T10:04:19","date_gmt":"2026-01-26T10:04:19","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/26\/new-phishing-attack-leverages-vercel-hosting-platform-to-deliver-a-remote-access-tool\/"},"modified":"2026-01-26T10:04:19","modified_gmt":"2026-01-26T10:04:19","slug":"new-phishing-attack-leverages-vercel-hosting-platform-to-deliver-a-remote-access-tool","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/26\/new-phishing-attack-leverages-vercel-hosting-platform-to-deliver-a-remote-access-tool\/","title":{"rendered":"New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool"},"content":{"rendered":"<p>    New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated phishing campaign active between November 2025 and January 2026 has been exploiting Vercel\u2019s legitimate hosting platform to distribute remote access tools to unsuspecting victims. <\/p>\n<p>The attack chain combines social engineering with trusted domain exploitation, making it particularly effective at bypassing traditional security layers. <\/p>\n<p>Attackers craft phishing emails using financially themed lures such as overdue invoices, payment statements, and shipping documents to pressure users into clicking <a href=\"https:\/\/cybersecuritynews.com\/hackers-hijacked-discord-invite-to-inject-malicious-links\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious links<\/a>.<\/p>\n<p>The campaign demonstrates a shift in threat actor tactics, moving beyond simple malware delivery to implement advanced evasion techniques. <\/p>\n<p>Victims receive emails containing urgency-driven language like \u201c43 days past due\u201d or threats of service suspension, compelling them to interact with hyperlinked content. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhCjPhqfEhASSkfvUS0cwItNgATbE1HBI520LplyIaJwk_DHI3C2K6YkAhSv-2HLkdnLRmU8yu_syGZtSZUIgnyvpJWZhvuIV2cCDSif9CHh1xQs9wdLUJ2JW42uyUVkThTCHu6D9wSGmafMGNuFVva9bgD6cjIr3vge_pJxaRX4va0VfOMl83Ok8MKpfk\/s16000\/%27Invoice%2520Details%27%2520phishing%2520example%2520%28Source%2520-%2520Cloudflare%29.webp?ssl=1\" alt=\"'Invoice Details' phishing example (Source - Cloudflare)\"><figcaption class=\"wp-element-caption\">\u2018Invoice Details\u2019 phishing example (Source \u2013 Cloudflare)<\/figcaption><\/figure>\n<\/div>\n<p>The attacker relies on Vercel\u2019s reputation as a trusted platform, which naturally bypasses email filters and creates a false sense of security for recipients. <\/p>\n<p>Some variants target specific regions, with Spanish-language emails posing as security update notifications, while others impersonate legitimate services like Adobe PDF viewers or financial portals.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEglrpF7PiD9nTjDr8oiux8T7zvQBykDY4xjT6AHItR_9_whUIXLFujA21cA7cAvo-geuLOJfgLxmKTQDZNZC-j9Dwd0rO5S3LDd4-S9r_TiaBiPe6yPQZ28KXy6r6TeyPcHA00F9otKQKzNGELSRpkeFVJi0CdWVfyoZKopJEgo8SdpEJmDlR5kdhDovJ4\/s16000\/A%2520phishing%2520email%2520impersonating%2520a%2520secure%2520document%2520signing%2520portal%2520%28Source%2520-%2520Cloudflare%29.webp?ssl=1\" alt=\"A phishing email impersonating a secure document signing portal (Source - Cloudflare)\"><figcaption class=\"wp-element-caption\">A phishing email impersonating a secure document signing portal (Source \u2013 Cloudflare)<\/figcaption><\/figure>\n<\/div>\n<p>Cloudflare analysts <a href=\"https:\/\/www.cloudflare.com\/en-gb\/cloudforce-one\/research\/report\/vercel-hosted-rmm-abuse-campaign-evolves-with-telegram-c2-for-victim-filtering\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this threat while examining Vercel abuse patterns and discovered that the campaign had evolved significantly since its initial documentation in June 2025 by CyberArmor. <\/p>\n<p>The researchers noted that threat actors implemented sophisticated Telegram-based filtering mechanisms designed to block security researchers and automated sandboxes from accessing the payload.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-through-browser-fingerprinting-and-conditional-delivery\"><strong>Infection Through Browser Fingerprinting and Conditional Delivery<\/strong><\/h2>\n<p>When victims click the malicious Vercel link, they encounter a technically advanced evasion mechanism before payload delivery. <\/p>\n<p>The attacker\u2019s infrastructure performs browser <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-uses-browser-fingerprinting\/\" target=\"_blank\" rel=\"noreferrer noopener\">fingerprinting<\/a>, collecting IP addresses, device types, browser information, and geographic location. <\/p>\n<p>This <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leak-270000-customers-tickets-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">harvested data<\/a> is exfiltrated to a threat-actor-controlled Telegram channel, where automated systems evaluate whether the victim represents a genuine target. <\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEghvloZCVJBPnlOI6hIpgO_CAJEqhQRKnMuyyieJP0gLjd0JW8KtYRN7fz-_77f7y4ry4_9wXLia7BcqZm2q1GGsI-OT3b9L4_HUYvjYz-F1RkiLYCxm9E-Vnerb96CcLpcPdxcSrg3l6_PcX-8f3au85V78cwznmvfvzDAO7AfC40BCf8Qh7pPOJhyphenhyphenFvM\/s16000\/A%2520specialized%2520lure%2520targeting%2520business%2520account%2520owners%2520%28Source%2520-%2520Cloudflare%29.webp?ssl=1\" alt=\"A specialized lure targeting business account owners (Source - Cloudflare)\"><figcaption class=\"wp-element-caption\">A specialized lure targeting business account owners (Source \u2013 Cloudflare)<\/figcaption><\/figure>\n<\/div>\n<p>Security researchers and suspicious connections are filtered out, while approved victims proceed to a fake document viewer interface.<\/p>\n<p>Users are then prompted to download files disguised as legitimate documents, with names like \u201cStatements05122025.exe\u201d or \u201cInvoice06092025.exe.bin.\u201d <\/p>\n<p>The payload itself is not custom <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> but rather a legitimate, signed copy of GoTo Resolve (formerly LogMeIn) remote access software. By leveraging this \u201cLiving off the Land\u201d technique, attackers bypass signature-based antivirus detection systems. <\/p>\n<p>Upon execution, the tool establishes connections to remote command servers, granting complete remote control and system access to threat actors.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-leverages-vercel-hosting-platform\/\">New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-leverages-vercel-hosting-platform\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool A sophisticated phishing campaign active between November 2025 and January 2026 has been exploiting Vercel\u2019s legitimate hosting platform to distribute remote access tools to unsuspecting victims. The attack chain combines social engineering with trusted domain exploitation, making it particularly effective at bypassing [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-10148","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10148"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10148"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10148\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10148"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10148"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10148"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}