A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
Brief
As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States.
The attackers impersonate trusted organizations and document types to trick victims into installing legitimate remote management software, giving them remote access to compromised systems.
Part I. Campaign Scope, Impact, and Defense
Threat Overview
Campaign overview based on ANY.RUN research
This phishing operation’s final goal is the remote control of the victim’s machine. A reusable fake-document kit delivers interchangeable, legitimate RMM software installer, which the attacker then abuses for hands-on access.
