Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OpenClaw AI Agent Exploits Gym API to Steal Workout Slot
August 10, 2026
Microsoft Teams to Gain New Security Detection Reporting Feature
August 9, 2026
Critical Metabase Vulnerability Exploited to Gain Admin Access
August 9, 2026
Home/Threats/NinjaOne RMM exploited to bypass malware detection
Threats

NinjaOne RMM exploited to bypass malware detection

Key Takeaways A sophisticated phishing campaign is actively deploying legitimate NinjaOne Remote Monitoring and Management (RMM) agents on victim systems. The attacks primarily target Brazilian...

Marcus Rodriguez
Marcus Rodriguez
June 12, 2026 4 Min Read
51 0

Key Takeaways

  • A sophisticated phishing campaign is actively deploying legitimate NinjaOne Remote Monitoring and Management (RMM) agents on victim systems.
  • The attacks primarily target Brazilian organizations across various sectors, including chemicals and advanced materials, with social engineering tactics tailored to local business culture.
  • Instead of traditional malware, threat actors trick users into installing a genuine RMM agent, granting them full remote control and bypassing conventional security detections.
  • The campaign utilizes advanced anti-analysis techniques, including browser fingerprinting, sandbox detection, and geofencing, to evade researchers.

Hackers Bypass Detection by Abusing Legitimate NinjaOne RMM Software

A new phishing campaign has emerged, leveraging a legitimate remote management tool to covertly compromise target systems without deploying traditional malware. This operation, detailed by researchers at Cato CTRL, the threat research division of Cato Networks, focuses on Brazilian organizations, where attackers manipulate employees into installing an authentic enterprise software agent, thereby granting themselves complete remote control over the compromised machines.

Table Of Content

  • Key Takeaways
  • Hackers Bypass Detection by Abusing Legitimate NinjaOne RMM Software
  • NinjaOne RMM: A Double-Edged Sword
  • Sophisticated Anti-Analysis Measures
  • What You Should Do
  • Indicators of Compromise (IoCs)

The attack chain initiates with a seemingly innocuous phishing email. Upon clicking a link, victims are redirected through a Google-based relay before landing on a fabricated business portal. This portal, presented in Portuguese, meticulously mimics common document-access workflows familiar to finance, procurement, and administrative personnel, effectively lowering their guard.

The critical element of this attack unfolds when the user proceeds to download. Instead of receiving the anticipated business document, the victim unknowingly installs a legitimate NinjaOne Remote Monitoring and Management (RMM) agent. This agent is pre-configured to establish a connection with infrastructure controlled by the attackers.

NinjaOne RMM: A Double-Edged Sword

Once the NinjaOne agent is successfully installed, attackers gain the same extensive access and control over the endpoint as a legitimate IT administrator. This includes capabilities such as monitoring device activity, executing remote commands, transferring files, deploying additional tools, and automating tasks. Crucially, because the software is a genuine, digitally signed enterprise application commonly found in corporate environments, most security solutions fail to flag it as malicious, allowing the compromise to proceed undetected.

The downloaded file itself was cunningly named “NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64,” maintaining the illusion of a fiscal document right through the installation process. In many instances, victims are reportedly contacted by phone, where an operator guides them to install the purported “required software” to access their document. This direct, operator-guided method eliminates the need for exploits, placing social engineering at the core of the attack strategy.

Sophisticated Anti-Analysis Measures

The phishing infrastructure employed in this campaign exhibits a high degree of sophistication, designed to actively thwart detection and analysis by security researchers. The malicious pages integrate browser fingerprinting, sandbox detection, and geofencing techniques to filter out investigators before delivering the payload.

During testing, the NinjaOne installer was exclusively served to visitors originating from Brazilian IP addresses, severely limiting visibility for anyone attempting to investigate from outside the region. Embedded JavaScript code meticulously tracked user interactions, including mouse movements, touch inputs, and scrolling behavior, to confirm the presence of a genuine human user. Developer comments written in Portuguese, such as “Bot preencheu o honeypot” (meaning “The bot filled the honeypot”), further underscore the deliberate efforts to block automated analysis systems.

Once these stringent checks were passed, the payload was discreetly delivered via a hidden iframe, with all traces of the delivery mechanism wiped approximately 30 seconds later. Despite these advanced protections, researchers uncovered a crucial lead: multiple attacker-controlled domains shared an identical Earth-themed wallpaper. Pivoting on this shared image filename allowed investigators to uncover additional campaign infrastructure.

Furthermore, investigators observed overlaps between the campaign’s infrastructure and elements previously associated with Venon RAT, a Brazilian threat operation known for using Rust-based malware. While this connection offers a strong indication, definitive attribution has not yet been established.

What You Should Do

  • Employee Training: Conduct regular and comprehensive cybersecurity awareness training, emphasizing the dangers of phishing, social engineering, and the importance of verifying unsolicited software installation requests.
  • Software Installation Policies: Implement strict policies regarding software installation. Users should never be permitted to install software to view documents or access portals without explicit IT approval.
  • Monitor RMM Agent Installations: Actively monitor your network for unauthorized installations of remote management software like NinjaOne. Alert on any new RMM agent deployments not initiated by IT.
  • Scrutinize Unusual Requests: Treat any unusual requests related to fiscal records, supplier communications, or complaint resolution workflows with extreme caution, especially if they involve downloading and installing software.
  • Targeted Awareness for Key Roles: Provide enhanced security awareness to employees in finance, procurement, and administrative departments, as these roles are frequently targeted by such social engineering tactics.
  • Endpoint Detection and Response (EDR): Utilize EDR solutions to detect anomalous behavior, even from legitimate software, which may indicate abuse.

Indicators of Compromise (IoCs):

Type Indicator Description
Domain r64[.]org Attacker-controlled phishing infrastructure domain
Domain hairdb[.]com Attacker-controlled phishing infrastructure domain
Domain lazybearpottery[.]net Attacker-controlled phishing infrastructure domain
Domain rectalmania[.]com Attacker-controlled phishing infrastructure domain
Domain sefaz[.]services Phishing domain impersonating Brazilian SEFAZ tax authority
Domain reclameaqui[.]services Phishing domain impersonating Brazilian complaint platform Reclame Aqui
File Name NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64 NinjaOne installer disguised as a Brazilian fiscal document used to establish attacker-controlled remote access

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

npm Campaign Targets Developers, Steals SSH Keys and Cloud Credentials

Next Post

Fancy Bear Abuses EdgeRouters, Cloud for Stealthy Cyberattacks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
OpenAI Pauses Astra Model Development to Assess Cybersecurity Risks
August 8, 2026
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us