A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
ID: 534bc540-28cc-5388-8709-99cf993e74d4
STIX ID: report--534bc540-28cc-5388-8709-99cf993e74d4
Feed Name: ANY.RUN's Cybersecurity Blog
A broad, active phishing campaign (tracked across 46 countries, US-first) uses a reusable fake-document kit to trick victims into running VBS/PowerShell that installs legitimate, signed RMM agents (GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian) for hands-on-keyboard access; operators rapidly rotate disposable hosting (notably Vercel deployments), use password-protected ZIPs, browser/IP fingerprinting and Telegram-based victim filtering to evade detection, and the analysis provides delivery-chain-focused detections (e.g., fmtt/font1.woff2, icons8-microsoft-word-94.png, secure.html → project/*.zip) and representative IOCs to prioritize blocking the delivery framework and unexpected RMM installs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
