Episode Details
Back to Episodes
A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
Description
This story was originally published on HackerNoon at: https://hackernoon.com/a-single-canadian-tax-lure-spread-into-a-46-country-us-first-rmm-campaign.
ANY.RUN uncovers a 46-country phishing campaign using fake tax documents, Vercel infrastructure, and legitimate RMM software for remote system access.
Check more stories related to undefined at: https://hackernoon.com/c/undefined.
You can also check exclusive content about #vercel-phishing-campaign, #rmm-abuse-phishing-campaign, #logmein-rescue-phishing, #ai-threat-intelligence, #legitimate-rmm-software, #remote-access-trojan, #goto-resolve-malware, #good-company, and more.
This story was written by: @anyrun. Learn more about this writer by checking @anyrun's about page,
and for more stories, please visit hackernoon.com.
A phishing campaign disguised as CRA T4 tax documents is part of a broader operation spanning 46 countries, with 45% of observed activity linked to the US. Instead of deploying conventional malware, attackers use legitimate RMM tools such as GoTo Resolve, LogMeIn Rescue, ScreenConnect, and ConnectWise to gain remote access. The campaign rotates Vercel apps, domains, and lures, making delivery-chain and behavioral detection more effective than product-based signatures.