NinjaOne RMM exploited to bypass malware detection
Key Takeaways A sophisticated phishing campaign is actively deploying legitimate NinjaOne Remote Monitoring and Management (RMM) agents on victim systems. The attacks primarily target Brazilian...
Key Takeaways
- A sophisticated phishing campaign is actively deploying legitimate NinjaOne Remote Monitoring and Management (RMM) agents on victim systems.
- The attacks primarily target Brazilian organizations across various sectors, including chemicals and advanced materials, with social engineering tactics tailored to local business culture.
- Instead of traditional malware, threat actors trick users into installing a genuine RMM agent, granting them full remote control and bypassing conventional security detections.
- The campaign utilizes advanced anti-analysis techniques, including browser fingerprinting, sandbox detection, and geofencing, to evade researchers.
Hackers Bypass Detection by Abusing Legitimate NinjaOne RMM Software
A new phishing campaign has emerged, leveraging a legitimate remote management tool to covertly compromise target systems without deploying traditional malware. This operation, detailed by researchers at Cato CTRL, the threat research division of Cato Networks, focuses on Brazilian organizations, where attackers manipulate employees into installing an authentic enterprise software agent, thereby granting themselves complete remote control over the compromised machines.
Table Of Content
The attack chain initiates with a seemingly innocuous phishing email. Upon clicking a link, victims are redirected through a Google-based relay before landing on a fabricated business portal. This portal, presented in Portuguese, meticulously mimics common document-access workflows familiar to finance, procurement, and administrative personnel, effectively lowering their guard.
The critical element of this attack unfolds when the user proceeds to download. Instead of receiving the anticipated business document, the victim unknowingly installs a legitimate NinjaOne Remote Monitoring and Management (RMM) agent. This agent is pre-configured to establish a connection with infrastructure controlled by the attackers.
NinjaOne RMM: A Double-Edged Sword
Once the NinjaOne agent is successfully installed, attackers gain the same extensive access and control over the endpoint as a legitimate IT administrator. This includes capabilities such as monitoring device activity, executing remote commands, transferring files, deploying additional tools, and automating tasks. Crucially, because the software is a genuine, digitally signed enterprise application commonly found in corporate environments, most security solutions fail to flag it as malicious, allowing the compromise to proceed undetected.
The downloaded file itself was cunningly named “NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64,” maintaining the illusion of a fiscal document right through the installation process. In many instances, victims are reportedly contacted by phone, where an operator guides them to install the purported “required software” to access their document. This direct, operator-guided method eliminates the need for exploits, placing social engineering at the core of the attack strategy.
Sophisticated Anti-Analysis Measures
The phishing infrastructure employed in this campaign exhibits a high degree of sophistication, designed to actively thwart detection and analysis by security researchers. The malicious pages integrate browser fingerprinting, sandbox detection, and geofencing techniques to filter out investigators before delivering the payload.
During testing, the NinjaOne installer was exclusively served to visitors originating from Brazilian IP addresses, severely limiting visibility for anyone attempting to investigate from outside the region. Embedded JavaScript code meticulously tracked user interactions, including mouse movements, touch inputs, and scrolling behavior, to confirm the presence of a genuine human user. Developer comments written in Portuguese, such as “Bot preencheu o honeypot” (meaning “The bot filled the honeypot”), further underscore the deliberate efforts to block automated analysis systems.
Once these stringent checks were passed, the payload was discreetly delivered via a hidden iframe, with all traces of the delivery mechanism wiped approximately 30 seconds later. Despite these advanced protections, researchers uncovered a crucial lead: multiple attacker-controlled domains shared an identical Earth-themed wallpaper. Pivoting on this shared image filename allowed investigators to uncover additional campaign infrastructure.
Furthermore, investigators observed overlaps between the campaign’s infrastructure and elements previously associated with Venon RAT, a Brazilian threat operation known for using Rust-based malware. While this connection offers a strong indication, definitive attribution has not yet been established.
What You Should Do
- Employee Training: Conduct regular and comprehensive cybersecurity awareness training, emphasizing the dangers of phishing, social engineering, and the importance of verifying unsolicited software installation requests.
- Software Installation Policies: Implement strict policies regarding software installation. Users should never be permitted to install software to view documents or access portals without explicit IT approval.
- Monitor RMM Agent Installations: Actively monitor your network for unauthorized installations of remote management software like NinjaOne. Alert on any new RMM agent deployments not initiated by IT.
- Scrutinize Unusual Requests: Treat any unusual requests related to fiscal records, supplier communications, or complaint resolution workflows with extreme caution, especially if they involve downloading and installing software.
- Targeted Awareness for Key Roles: Provide enhanced security awareness to employees in finance, procurement, and administrative departments, as these roles are frequently targeted by such social engineering tactics.
- Endpoint Detection and Response (EDR): Utilize EDR solutions to detect anomalous behavior, even from legitimate software, which may indicate abuse.
Indicators of Compromise (IoCs):
| Type | Indicator | Description |
|---|---|---|
| Domain | r64[.]org | Attacker-controlled phishing infrastructure domain |
| Domain | hairdb[.]com | Attacker-controlled phishing infrastructure domain |
| Domain | lazybearpottery[.]net | Attacker-controlled phishing infrastructure domain |
| Domain | rectalmania[.]com | Attacker-controlled phishing infrastructure domain |
| Domain | sefaz[.]services | Phishing domain impersonating Brazilian SEFAZ tax authority |
| Domain | reclameaqui[.]services | Phishing domain impersonating Brazilian complaint platform Reclame Aqui |
| File Name | NinjaOne-Agent-DocumentoFiscal21782856920262001238-Sede-Auto-x86-64 | NinjaOne installer disguised as a Brazilian fiscal document used to establish attacker-controlled remote access |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.