ZeroHour
ANY.RUNpublished ()ingested ShiFu

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

mediumPhishing & fraud exploited in the wildimportance 45
AI summary · glm-5.3-flash

A phishing campaign using fake Canada Revenue Agency tax documents has expanded to 46 countries, with 45% of activity targeting the US via RMM tools.

ANY.RUN analysis traced a campaign that began with fake Canada Revenue Agency (CRA) T4 tax documents and grew into a broader remote-access operation spanning 46 countries. The United States accounts for 45% of observed activity. Attackers impersonate trusted organizations and document types to trick victims into installing remote monitoring and management (RMM) tools.

  • Initial lure uses fake CRA T4 tax documents
  • Campaign spans 46 countries; US accounts for 45% of activity
  • Victims are socially engineered into installing RMM tools
  • Attackers impersonate trusted organizations to gain credibility
Full article

As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States. The attackers impersonate trusted organizations and document types to trick victims into […] The post A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign appeared first on ANY.RUN's Cybersecurity Blog.

This source does not provide full text. Read it at any.run.