New Phishing Attack Exploits Vercel to Host and Deliver Remote Access Malware
A recent phishing campaign exploiting the Vercel hosting platform has been identified, active since at least November 2025, and demonstrating increasing sophistication.
A recent phishing campaign exploiting the Vercel hosting platform has been identified, active since at least November 2025, and demonstrating increasing sophistication.
The campaign utilizes an "inherited trust" technique. Attackers distribute phishing emails with financial or business-related themes, such as unpaid invoices or payment statements, embedding links to *.vercel.app domains. These domains are less likely to be flagged by email filters due to their legitimate use.
The linked pages mimic secure PDF viewers, financial portals, document-signing services, or software download pages. In some instances, the attackers impersonate IT or support personnel, directing victims to install supposed fixes via the Vercel page.
Initially documented by CyberArmor in June 2025, the campaign has evolved from simple file delivery to a conditional infection chain, utilizing Telegram for filtering and GoTo Resolve for remote access.
The phishing process involves several stages:
Initial email prompts the victim to click a Vercel link. The linked page gathers browser fingerprinting data, including IP address, location, and device details. This data is sent to a Telegram channel controlled by attackers for decision-making. If the victim is deemed a valid target, the page presents a fake viewer or invoice and prompts a file download, e.g., "Statements05122025.exe". The downloaded file is a signed installer for GoTo Resolve, which allows remote access without detection by antivirus software.
Once executed, GoTo Resolve provides full remote control of the victim's system.
To mitigate this threat, organizations should focus on:
Time-of-click URL analysis and detection of service abuse and brand impersonation. Monitoring of vercel.app and similar subdomains. Implementing application control policies to restrict installation of remote support tools. User education emphasizing that known domains do not guarantee security.
Cloudflare Email Security has developed detection rules for this activity, including SentimentCM.Banking.Invoice.Service_Abuse.Vercel.Link, which have recorded significant hits, indicating widespread threat activity.
Indicator/Domain Description / Status
duepaymentinvoiceattached[.]vercel[.]app Primary dropper URL
paymentrequestoninvoicedueattached[.]vercel[.]app Confirmed dropper
These domains are less likely to be flagged by email filters due to their legitimate use.
invoice-110493[.]vercel[.]app Confirmed dropper
olierinvoiceunpaidmmpaid[.]vercel[.]app Confirmed dropper
paidrepotstatementinvoice[.]vercel[.]app Confirmed dropper
unpaidbillrequestedservicedetails[.]vercel[.]app Likely malicious (matching TTPs)
requestpaymentdueattachedts[.]vercel[.]app Likely malicious (matching TTPs)
outstandingstatementdetailsattachedrb[.]vercel[.]app Likely malicious (matching TTPs)
salesrepacctstatementdetails[.]vercel[.]app Likely malicious (matching TTPs)
remityourpendingpaymentdts[.]vercel[.]app Likely malicious (matching TTPs)
unpaidinvoiceremitaath[.]vercel[.]app OSINT confirmed
waybill-deliveryticket[.]vercel[.]app OSINT confirmed
invstatement2025[.]vercel[.]app OSINT confirmed
invstatement[.]vercel[.]app OSINT confirmed
windowscorps[.]vercel[.]app OSINT confirmed
invoices-attachedpdf[.]vercel[.]app OSINT confirmed
dhl-delivery-report[.]vercel[.]app OSINT confirmed
dhl-shipment-detail[.]vercel[.]app OSINT confirmed
express-delivery-note[.]vercel[.]app OSINT confirmed
docsignstatements[.]vercel[.]app OSINT confirmed
shipment-docspdf[.]surge[.]sh OSINT confirmed (Surge abuse)
mail[.]blta[.]ro OSINT associated domain
findhome[.]cl OSINT associated domain
Based on reporting by GBHackers.
