An active phishing campaign targeting Brazilian organizations which attackers are tricking victims into downloading a legitimate remote management tool called NinjaOne.
This tactic highlights a growing reality in the threat landscape, attackers no longer need exotic, complex malicious code to breach corporate networks. Familiar business workflows and trusted software are often enough to establish a foothold.
The attackers focus heavily on the chemicals and advanced materials sector. However, the campaign threatens anyone who regularly handles invoices, tax documents, or supplier communications.
The lure begins with a phishing email that redirects users to realistic, Portuguese-language web portals.
These fake landing pages impersonate well-known Brazilian services, setting a clever trap for unsuspecting employees who view these interactions as routine.

Fake Fiscal Docs Deploy NinjaOne
Once a user clicks the initial phishing link, a redirection chain masks the final destination using legitimate third-party infrastructure.
The attackers use domains that mimic trusted Brazilian services, such as SEFAZ (the state tax authority) and Reclame Aqui (a popular consumer complaint platform).
These themes are highly effective because they blend perfectly into the daily operations of finance, procurement, and administrative staff.
When victims land on the fake portal, they are prompted to complete a security verification to access a protected business document.

The attackers use terms like “secure downloads” and “fiscal documents” to build trust. However, clicking the download button does not trigger a PDF download.
Instead, the site uses a hidden iframe to silently trigger the download of a NinjaOne Remote Monitoring and Management (RMM) installer. To maintain the illusion, the file is cleverly renamed to look like a tax document, such as “DocumentoFiscal”.
According to catonetworks research, why go through all this trouble to install a legitimate IT administration tool? NinjaOne is a powerful enterprise platform designed for endpoint monitoring, software deployment, and remote troubleshooting.
By installing it on a victim’s machine, attackers gain persistent remote access to the compromised system.
They can quietly execute commands, transfer files, and deploy additional tools while hiding behind digitally signed, commercial software. This strategy makes detection significantly harder for traditional security solutions.
Despite the campaign’s sophisticated anti-analysis measures, the attackers made a simple operational mistake that allowed researchers to map their network.
Several malicious domains shared an identical Earth-themed wallpaper image when accessed directly. By pivoting on this specific image file, threat hunters discovered a broader network of attacker-controlled domains.
This investigation also revealed potential operational overlaps with previous campaigns involving Venon RAT, a known Brazilian cybercrime operation.
Indicators of Compromise
| Indicator Type | Indicator | Description |
|---|---|---|
| Domain | r64[.]org | Attacker-controlled infrastructure |
| Domain | hairdb[.]com | Attacker-controlled infrastructure |
| Domain | lazybearpottery[.]net | Attacker-controlled infrastructure |
| Domain | rectalmania[.]com | Attacker-controlled infrastructure |
| Domain | sefaz[.]services | Phishing domain impersonating Brazilian tax authority (SEFAZ) |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.