Fake tax and shipping lures push RMM installs across 46 countries

A 46-country phishing wave leans on fake tax and shipping forms to push legitimate RMM tools, with the US the top target.

CSBadmin
2 Min Read

A phishing operation that uses phony tax forms, shipping notices, and invoices to push legitimate remote monitoring and management software has spread across 46 countries, with the United States drawing roughly 45 percent of observed activity. ANY.RUN researchers tied 601 cases to the campaign, making the US its top target.

The lures adapt to the mark: Canada Revenue Agency tax documents, UPS-style shipping messages, Adobe PDFs, US Social Security Administration themes, and assorted invoices. Victims who bite end up installing legitimate RMM tools that attackers then misuse for remote access, a pattern that blurs the line between sanctioned software and intrusion tooling.

The delivery chain rotates fast. Researchers logged 425 phishing kit URLs across 240 hosts, and 94 percent of those hosts lived for a single day. Operators leaned on Vercel, GitHub Pages, Netlify, and compromised websites, staging payloads on Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox, and GoFile.

Shared fingerprints such as a recurring font file and a fixed page-to-archive delivery structure let analysts tie the rotating infrastructure to one operation. Education, technology, and government topped the targeted industries, with banking, finance, and manufacturing also prominent. ANY.RUN argues detection cannot rest on single domains or malware verdicts when both are disposable, so security teams need the behavioral context around RMM use to tell routine support from a phish.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.