logo

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

ID: 534bc540-28cc-5388-8709-99cf993e74d4

STIX ID: report--534bc540-28cc-5388-8709-99cf993e74d4

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: ShiFu

...
...

A broad, active phishing campaign (tracked across 46 countries, US-first) uses a reusable fake-document kit to trick victims into running VBS/PowerShell that installs legitimate, signed RMM agents (GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, ITarian) for hands-on-keyboard access; operators rapidly rotate disposable hosting (notably Vercel deployments), use password-protected ZIPs, browser/IP fingerprinting and Telegram-based victim filtering to evade detection, and the analysis provides delivery-chain-focused detections (e.g., fmtt/font1.woff2, icons8-microsoft-word-94.png, secure.html → project/*.zip) and representative IOCs to prioritize blocking the delivery framework and unexpected RMM installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.