A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
ANY.RUN uncovers a 46-country phishing campaign using fake tax documents, Vercel infrastructure, and legitimate RMM software for remote system access.
The phishing operation, initially aimed at Canadians with fake Canada Revenue Agency (CRA) T4 tax documents, is part of a broader remote-access campaign affecting 46 countries. The attackers use a reusable fake-document kit to deliver legitimate remote management software installers, enabling them to gain remote access to compromised systems.
The payload, signed legitimate RMM software, can bypass signature-based antivirus systems. The campaign targets various industries, with education, technology, and government appearing prominently. It is important to note that this is not a one-off incident, as the activity window extends from January 2026 to present, with a steady 17–33 cases per month.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.