Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New Phishing Attack Exploits Vercel to Host and Deliver Remote Access Malware

A recent phishing campaign exploiting the Vercel hosting platform has been identified, active since at least November 2025, and demonstrating increasing sophistication.

A recent phishing campaign exploiting the Vercel hosting platform has been identified, active since at least November 2025, and demonstrating increasing sophistication.

The campaign utilizes an "inherited trust" technique. Attackers distribute phishing emails with financial or business-related themes, such as unpaid invoices or payment statements, embedding links to *.vercel.app domains. These domains are less likely to be flagged by email filters due to their legitimate use.

The linked pages mimic secure PDF viewers, financial portals, document-signing services, or software download pages. In some instances, the attackers impersonate IT or support personnel, directing victims to install supposed fixes via the Vercel page.

Initially documented by CyberArmor in June 2025, the campaign has evolved from simple file delivery to a conditional infection chain, utilizing Telegram for filtering and GoTo Resolve for remote access.

The phishing process involves several stages:

Initial email prompts the victim to click a Vercel link. The linked page gathers browser fingerprinting data, including IP address, location, and device details. This data is sent to a Telegram channel controlled by attackers for decision-making. If the victim is deemed a valid target, the page presents a fake viewer or invoice and prompts a file download, e.g., "Statements05122025.exe". The downloaded file is a signed installer for GoTo Resolve, which allows remote access without detection by antivirus software.

Once executed, GoTo Resolve provides full remote control of the victim's system.

To mitigate this threat, organizations should focus on:

Time-of-click URL analysis and detection of service abuse and brand impersonation. Monitoring of vercel.app and similar subdomains. Implementing application control policies to restrict installation of remote support tools. User education emphasizing that known domains do not guarantee security.

Cloudflare Email Security has developed detection rules for this activity, including SentimentCM.Banking.Invoice.Service_Abuse.Vercel.Link, which have recorded significant hits, indicating widespread threat activity.

Indicator/Domain Description / Status

duepaymentinvoiceattached[.]vercel[.]app Primary dropper URL

paymentrequestoninvoicedueattached[.]vercel[.]app Confirmed dropper

These domains are less likely to be flagged by email filters due to their legitimate use.
Brooke Sanders · Thehackingpost

invoice-110493[.]vercel[.]app Confirmed dropper

olierinvoiceunpaidmmpaid[.]vercel[.]app Confirmed dropper

paidrepotstatementinvoice[.]vercel[.]app Confirmed dropper

unpaidbillrequestedservicedetails[.]vercel[.]app Likely malicious (matching TTPs)

requestpaymentdueattachedts[.]vercel[.]app Likely malicious (matching TTPs)

outstandingstatementdetailsattachedrb[.]vercel[.]app Likely malicious (matching TTPs)

salesrepacctstatementdetails[.]vercel[.]app Likely malicious (matching TTPs)

remityourpendingpaymentdts[.]vercel[.]app Likely malicious (matching TTPs)

unpaidinvoiceremitaath[.]vercel[.]app OSINT confirmed

waybill-deliveryticket[.]vercel[.]app OSINT confirmed

Advertisement

invstatement2025[.]vercel[.]app OSINT confirmed

invstatement[.]vercel[.]app OSINT confirmed

windowscorps[.]vercel[.]app OSINT confirmed

invoices-attachedpdf[.]vercel[.]app OSINT confirmed

dhl-delivery-report[.]vercel[.]app OSINT confirmed

dhl-shipment-detail[.]vercel[.]app OSINT confirmed

express-delivery-note[.]vercel[.]app OSINT confirmed

docsignstatements[.]vercel[.]app OSINT confirmed

shipment-docspdf[.]surge[.]sh OSINT confirmed (Surge abuse)

mail[.]blta[.]ro OSINT associated domain

findhome[.]cl OSINT associated domain

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories