A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States.
The attackers impersonate trusted organizations and document types to trick victims into installing legitimate remote management software, giving them remote access to compromised systems.
Part I. Campaign Scope, Impact, and Defense
Threat Overview
Campaign overview based on ANY.RUN research
This phishing operation’s final goal is the remote control of the victim’s machine. A reusable fake-document kit delivers interchangeable, legitimate RMM software installer, which the attacker then abuses for hands-on access.
Because the payload is signed commercial software, ordinary signature-based antivirus cannot flag it. Its activity resembles ordinary remote administration.
The campaign uses multiple lures, including the US Social Security Administration, Adobe PDF documents, invoices, VAT notices, and...
Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE