Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

Researchers studying cybersecurity are alerting people to a new campaign that has been using trial versions of commercial remote monitoring and management (RMM) software since January 2025 to target Portuguese-speaking users in Brazil.

According to a report released Thursday by Cisco Talos researcher Guilherme Venere, the spam message leverages the Brazilian electronic invoice system, NF-e, as a lure to trick consumers into clicking hyperlinks and accessing harmful files hosted in Dropbox.

In order to deceive victims into clicking on fake Dropbox links that lead to a binary installer for the RMM program, the attack chains start with well constructed spam emails that seem to be from financial institutions or mobile phone carriers and warn of past-due bills or unpaid invoices.

PDQ Connect and N-able RMM Remote Access are two noteworthy RMM tools that were noted read more about Initial Access Brokers Target Brazil Execs via NF-e Spam and Legit RMM Trials

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *