ZeroHour

Search: “canada”

234 stories

A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

A phishing campaign using fake Canada Revenue Agency tax documents has expanded to 46 countries, with 45% of activity targeting the US via RMM tools.

ANY.RUN analysis traced a campaign that began with fake Canada Revenue Agency (CRA) T4 tax documents and grew into a broader remote-access operation spanning 46 countries. The United States accounts for 45% of observed activity. Attackers impersonate trusted organizations and document types to trick victims into installing remote monitoring and management (RMM) tools.

ANY.RUN · 21d agoPhishing & fraud in the wild

The Money Mule Solution: What Every Scam Has in Common

CYBERA's money mule intelligence, now in Recorded Future's Payment Fraud Intelligence, targets the shared exit point of $450B-$1T annual scam losses.

Scams, especially authorized push payment fraud, do not require a breach; Global Anti-Scam Alliance estimated ~$450B in 2025 losses while CYBERA co-founder Claudio Staub puts the real figure near $1 trillion when underreporting is counted. Every scam needs a mule account to receive funds, so CYBERA uses agentic personas to engage active scammers and extract verified mule account details before payments occur, now available as an add-on to Recorded Future's Payment Fraud Intelligence. CYBERA collected over 16,000 confirmed mule accounts across 72 countries in H2 2025, finding 28% remained active 30 days or more after identification, including one account in 25 engagements. In Europe 51% of mule accounts sat at neobanks and fintechs, while outside Europe 69% were at major banks; regulatory pressure like the UK's APP reimbursement mandate is raising the stakes for institutions.

Recorded Future · 16d agoPhishing & fraud

The Smishing Deluge: China-Based Campaign Flooding Global Text Messages

Unit 42 attributes a global smishing campaign with 194,000+ phishing domains impersonating tolls, banks, and couriers to the Smishing Triad.

Palo Alto Unit 42 attributes ongoing smishing texts about toll violations and package misdelivery to the Smishing Triad, targeting U.S. residents since April 2024. Researchers identified 194,345 FQDNs across 136,933 root domains registered since January 2024, mostly via Hong Kong registrar Dominet (HK) Limited with Chinese nameservers and hosting concentrated on U.S. cloud services. The decentralized campaign impersonates banking, cryptocurrency, e-commerce, healthcare, law enforcement, and social media services, and its scale points to a large phishing-as-a-service operation. Phishing pages harvest national ID numbers such as Social Security numbers, home addresses, payment details, and login credentials.

Palo Alto Unit 42 · 29d agoPhishing & fraud in the wild