The Good Tech Companies - A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign
Episode Date: September 1, 2026This story was originally published on HackerNoon at: https://hackernoon.com/a-single-canadian-tax-lure-spread-into-a-46-country-us-first-rmm-campaign. ANY.RUN uncovers ...a 46-country phishing campaign using fake tax documents, Vercel infrastructure, and legitimate RMM software for remote system access. Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #vercel-phishing-campaign, #rmm-abuse-phishing-campaign, #logmein-rescue-phishing, #ai-threat-intelligence, #legitimate-rmm-software, #remote-access-trojan, #goto-resolve-malware, #good-company, and more. This story was written by: @anyrun. Learn more about this writer by checking @anyrun's about page, and for more stories, please visit hackernoon.com. A phishing campaign disguised as CRA T4 tax documents is part of a broader operation spanning 46 countries, with 45% of observed activity linked to the US. Instead of deploying conventional malware, attackers use legitimate RMM tools such as GoTo Resolve, LogMeIn Rescue, ScreenConnect, and ConnectWise to gain remote access. The campaign rotates Vercel apps, domains, and lures, making delivery-chain and behavioral detection more effective than product-based signatures.
Transcript
Discussion (0)
This audio is presented by Hacker Noon, where anyone can learn anything about any technology.
A single Canadian tax lure spread into a 46 country, US-first RMM campaign.
By any run, as any, run analysis shows, a campaign that initially appears to target Canadian
with fake Canada revenue agency, CRA T4 tax documents is actually part of a much broader
remote access campaign spanning 46 countries, with 45% of observed activity associated with the
United States. The attackers impersonate trusted organizations and document types to trick victims
into installing legitimate remote management software, giving them remote access to compromised systems.
Part 1 campaign scope, impact, and defense. Threat overview this fishing operation's final goal
is the remote control of the victim machine. A reusable fake document kit delivers interchangeable,
legitimate RMM software installer, which the attacker then abuses for hands own access. Because the
Payload assigned commercial software, ordinary signature-based antivirus cannot flag it.
Its activity resembles ordinary remote administration.
View this malware analysis in TI reports the campaign uses multiple lures, including the U.S.
Social Security Administration, Adobe PDF documents, invoices, VAT notices, and shipping communications,
allowing the same attack model to target victims across different regions and business contexts.
campaign profile attribute assessment threat type fishing delivering RMM as rat for living off
the land remote access family fake document to RMM kit.
The CRAT forward lure is one arm of a broader FMTT font-length family severity high, hands-on
keyboard remote access sophistication capable, kid-based delivery, Lalbon RMM abuse, password-protected
archive, telegram-based victim filtering, built entirely on legitimate signed tooling payload
ad sign RMM installers abused as remote access trojans. Products are interchangeable and include
GoTo Resolve. Log Main Rescue. Etarian in this arm. Screen ConnectWise in sibling arms
impersonated brands Canada Revenue Agency, 2025T4 Form, SSA, VAT, Auto, DocuSign, Adobe PDF, overdue
invoices, shipping documents attribution campaign level based on shared delivery kit handwriting,
no-named threat actor. Whether this is one option,
or a shared fishing as a service kit remains unknown activity window January 2026 to present.
Steady 17 to 33 kit cases per month statistics and victimology two scopes are important here.
The CRA T-4ward Arm with 137 observed cases and THE broader fake document family,
covering 425 kit URLs across 240 hosts and 601 cases with geographic and industry context.
Activity grew from a single observed case in January.
January 2026 to a steady 17 to 33 cases per month. Because the final payload is legitimate-signed
RMM software, cases are tracked through shared kid assets rather than malware family verdicts,
which would significantly undercount the campaign. Geographically, the broader family is U.S.
first, while the CRA T-4 arm is Canada first. North America accounts for 61% of family cases,
but activity spans 46 countries, with 35 contributing 1% or less.
Canada represents 16% of the broader family but 33.3% of the CRA T4RM, consistent with deliberate
targeting around the Canadian tax lure. Across industries, education, technology, and government
appear prominently in BOTD datasets. Technology figures may be influenced by higher security team
submission rates, while the exposure seen in education and government is more consistent with
genuine targeting. Banking, manufacturing, and finance also feature prominently.
aligning more closely with the campaign's invoice and VAT-themed lures.
These figures represent where campaign samples were observed rather than-confirmed compromises,
so they should be treated as indicators of targeting focus and a proxy for the potential victim
population. What to take back to your SOC team for security leaders, the key takeaway is that
defenses need to be product agnostic. This campaign abuses legitimate, signed RMM software and can
switch between vendors, so controls built around a specific tool or AVU,
verdict will leave gaps. Ensure your society focuses on the delivery chain and unauthorized remote access
activity instead. Treat the RMM install itself as a signal, whatever the product. GoTo Resolve,
log main rescue, screen connect, connect-wise, and Atari have all been abused in this campaign.
Detection should focus on how the software reaches the environment, particularly installations
originating from new free hosting domains are compromised WordPress pages, rather than on the RMM product
itself. Build detection around persistent campaign patterns, disposable vercell infrastructure rotates
rapidly, 94% of 240 observed hosts appeared for only a single day. Instead of relying primarily on
domains, prioritize stable kit indicators, including the FMTT, font 1. Waf 2, icons 8 Microsoft Word
94, PNG asset, and the secure HTML right pointing arrow project, asterisk, zip chain,
Account for password-protected archive delivery.
The campaign pairs fake document pages with password-protected zip files
and provides the password to the victim, helping payloads evade automated inspection.
Mail-layer controls and user awareness should account for this delivery pattern.
Baseline authorized remote access tooling.
Maintain an inventory of approved RMM products and ensure the society can quickly identify
unexpected installations or activity.
Give analysts behavioral and threat context in one investigation work.
In this analysis, any runs interactive sandbox exposed the delivery chain, browser activity,
scripts, and network requests, while threat intelligence look up expanded persistent indicators
into the wider campaign.
Explore any run for your team part two.
Technical malware analysis.
Introduction new.
Versal app deployments appear more or less constantly, each only day solved.
One of them, filling confirmation.
Versel app had been registered just one day before it was observed.
reserved. Verselle suits the operator well. Every deployment comes with valid TLS, a trusted domain,
and one command redeployment. All this gives the lures the reputation needed to clear mail filters
while remaining cheap enough to abandon at will. The activity has continued since January 2026 at a
steady monthly pace, with 18 to 57 new kit hosts appearing each month. Cloudflare,
Casilla, Inki, and Cyber Armor have also reported on this activity, with findings consistent with
what follows here. The delivery chain the attack begins with a phishing email linking to a disposable.
Versel app page disguised as a legitimate document. The CRA T4 Lour is one example, alongside SSA,
VAT, invoice, shipping, and other document-themed variants. The page redirects to secure HTML,
which provides an access code and downloads a password protected zip, the payload.
Once the victim extracts and runs the VBS script inside, power-s,
shell downloads and installs a legitimate RMM agent, giving the operator hands on keyboard remote access.
The kit's handwriting revealed via advanced URL analysis using any. Runs in browser data
inspection, we reconstructed the full browser side chain, including DOM changes, redirects, page
content, and screenshots of what the victim sees at each stage. Every deployment ships essentially
the same page, byte for byte. Several recurring DOM elements reveal the kit's distinctive handwriting,
an empty title. A at Fontface declaration for font family. FMTT. Sourcing URL, IMG, font 1. Waf2. The shared font
that links the broader family. IMGSRC equals IMG, icons 8 Microsoft Word 94. PNG, ID equals, FD,
alt equals PDF icon, a word icon persistently mislabeled as PDF icon. A hashtag RL Red Spinner
A three-hop meta-refresh chain, root page right-pointing arrow secure.
HTML right-pointing arrow project, less than lure greater than.
Zip.
The recurring, downloading 2025T4 form, and access code text.
For additional cover, the kit opens a harmless decoy PDF through legitimate OneDrive infrastructure,
1DRIV.
Ms. OneDrive, Live, Com, and Canada East 1MediaP.
SVC.
Ms. Its purpose is simply to make the download appear routine to the victim.
Execution behavior using static discovering in any.
Runs interactive sandbox, we inspected the VBS script responsible for launching the next stage of the attack.
The chain progresses only after the victim enters the on-page access code.
This unlocks a single VBS script that uses file system object to launch PowerShell.
X-Ean download the next stage.
Register with any.
RUN-POWShell does the rest.
It skips the user profile, introduces a sleep-delay tovade timing-based analysis,
writes binary data to a stream, and downloads and installs the RMMMSI.
Once installed, the RMM agent gives the operator live, hands-on keyboard access to the system.
Evasion Evasion operates across multiple stages of the delivery chain.
The first layer is the archive, project, less than lure greater than.
Zip returns HTT-T-P-200 but remains password encrypted, leaving auto-eventingerted, leaving
automated pipelines with an inert zip they canotopin. The VBS inside is extracted and executed
only after the victim enters Theon page access code. The second layer sits in front of payload
delivery. The page fingerprints the browser, IP address, and geolocation using fingerprint JS,
an H-C-A-P-T-C-H-A challenge, and a green spinner gate. On some pages, the results are relayed
Toopi, Telegram, org, allowing the payload to be served only to visitors that pass the checks
while filtering out suspected analysis environments. The PowerShell stage adds timing-based evasion
by calling sleep before reaching out for the MSI installer. HTTP request analysis in any
runs interactive sandbox made these delivery and evasion flows visible. Following the network
trail revealed a broader, highly distributed infrastructure. Network infrastructure delivery infrastructure,
the family includes 82 code identical VERSL apps, each observed for only a single day,
alongside GitHub pages, Netlify, compromise legitimate websites, and throwaway domains.
Versel is particularly useful to the operator because each new deployment inherits valid TLS and domain reputation.
Payload staging. RMM installers are staged across rotating infrastructure,
including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, GoFile.
I.O. Dropbox, compromised sites, and raw IP hosts. RMM infrastructure, the remote access product is
interchangeable. At least five legitimate RMM products have appeared across the family, while the delivery
chain remains largely unchanged. The evidence behind each product is uneven, which bounds what any
per product signature can cover. RMM product what backs it install, network artifacts measured
LogMe in Rescue, Resolve 46 cases in this arm. Captured MSI LogMe in Resolve underscore unattended.
MSI yes. Logme in Rescue Mutex on host go to resolve dominant product by network telemetry
in this arm yes, TLS SNI and DNS Togato resolve. Comscreen Connect 204 family cases. Outside this arm
identified by case tag connect WISE 106 family cases. Outside this arm identified by case tag I Tarian
one case know those measured artifacts cover the go-to and log main slot only. The RMM stage is the
thinnest layer of evidence in the chain. 20 of the 137 arm cases are observed fetching the MSI,
while the rest stop at the password protected archive, and the same MSI appears in 150 cases
index-wide, SWA is staged across delivery arms beyond this kit. Neither the staging host nor the
RMM backend identifies the operator. The MS is its on shared, abused cloud story.
and the backend is each vendor's own infrastructure, so neither layer establishes that one operator
is behind all OFIT. The delivery kit's handwriting is what ties the activity together. The fact
that the product in the RMM slot changes between arms is another reason why this slot is the weakest
layer for building a durable signature. Cluster expansion the CRA T-4arm is one part of a broader delivery
framework whose document themes, domains, and RMM payloads change while the underlying kit remains stable.
The shared FMTT web font, IMG, font 1. Waf2, provides a particularly strong pivot into that wider
activity. Arm how to recognize it payload, behavior cray, T4 Word on Vercelicons 8 Microsoft Word 94.
PNG, it equals FD, alt equals PDF icon, plus secure.
HTML Plus project, asterisk, zip on, Versel, app.
Access code ZIPP password zip to VB,
to PowerShell to Go to Resolve, Log Me in Rescue MSI Adobe PDF, SSA, compromised WordPress
Siblings same FMTT font 1.
Waf2 font, paths, PDF viewer updater, admin, SSAA, WP content, file, screen connect, connect-wise,
other RMM tooling, plus telegram victim filtering to determine whether this is a shared
fishing as a service kit with several affiliates, we can use Thread Intelligence Lookup for
cluster expansion. URL. Asterisk IMF font 1. Waf 2 inches ORURURL. Asterisk. Icons 8 Microsoft Word
94 PNG, Orsha 256. 51F0 C. 172 C.1 C.27 M.A. 97-E.7 million
64,380E 597,076,350A6B-286 AB-286-N.
7 C.C.B 42 inches. The query returns 601 analysis cases across the three indicators,
at the time of writing. The font alone links 425 distinct kit URLs across 240 hosts and
155 IPs between February 5th and July 29, 2026, exposing activity well beyond the CR.
A T-4-arm. The same fingerprint produced no matches across roughly 46,000 cases from 10 unrelated
malware families, supporting its use as an operation-specific marker rather than a generic web artifact.
Try Ti look up for your S-O-C-I-N-F-R-A-S-T-U-R-E footprint the font 1.
Waf2 Query provides a direct measure of the family's delivery infrastructure.
Across 174 days, it identified 425 distinct kit UR.A.
on 240 hosts resolving to 155 IPs.
Measure value distinct kit URL's 425 unique hosts serving the kit 240 unique resolving IPs 155
observation window the 5th of February to the 29th of July 2026.
174 days.
Hosts seen within a single day 225 of 240, 94%.
Hosts seen over three days or less 228 of 240, 95% longest-lived host doc shared.
Org, 23 days busiest host dashboard UAT.
Pay N Now, Com, 45 kit URLs in 11.
Five days the hosting breakdown shows how this infrastructure is distributed across different
host types.
Hosting type hosts kit URLs conventional websites, compromised or stood up,
117,257 Versailles.
Asterisk.
Versel, App 8,282 throwaway registrations on cheap TLDs.
VU.S.B.S.C.F.D. I see you. Top.1.CU. Shop. Online. Site. 3,265 dynamic DNS. D DNS King.
comm swoop to me let's go to me net to me me 719 netlify asterisk netlify app 11 backblaze b2 f004 backblaze ab to com 11 total 240,4
push button deployment platforms account for 83 of the 240 hosts with vurcell supplying 82 of them
every vercell app was observed on exactly one day with exactly one kit URL and was never
reused, indicating a one app per lure deployment model that makes domain level blocking quickly
obsolete. Lure theme in the Vercel subdomain apps CRA T4 Techs, 2025 T4 AB 1,109,061, Kratak summary 1,7,341,
official summary by Cray, 27 generic shared document, file transfer, shared doc 820,848,10,641,
New files shared.
25 invoice, payment, VAT.
Invoice 49,883 due.
Payment resell PT 8 Adobe, PDF, Flash Updator, Adobe UPD, PDF viewer new, flash updater.
7 streaming, invite, social, live event stream, kick to gather now.
7 USSA, Social Security.
Social Security Statement received 03204 shipping and logistics.
UPSAWB 4,290,324, four total 82 new hosts appear at a steady clip, while Vrcell deployments arrive in bursts,
23 new apps in March, at the height of Canadian T4 season, and 20 more in July.
Month, 2026, new hosts of which Vercel Apps Kit URLs seen February 18,629 March 432,359 April 451,76,
May 4,416, 115 June 33,759 July to 29th, 572087 total 24,082,425.
The infrastructure also splits into two distinct URL patterns.
All 83 Verselle and Netlify apps serve the kid directly from IMG, font 1.
Waf 2, while 110 other hosts use per recipient paths in the form, FTX, less than slug greater
than less than Epic greater than less than hex greater than. The embedded Unix time stamps reveal the
campaign's operational tempo. The median link was first observed just 32 minutes after generation,
and 77% within 24 hours. This strongly suggests that links are generated per recipient and used
almost immediately. Reputation follows the same divide of 425 URLs, 23 were already rated malicious
when observed, all hosted on cheap TLD throwaway domains. None were Vercel apps, suggesting that the
platform provides the clean domain reputation the operator's own disposable domains lack.
Conclusion, this analysis uncovered a 46 country, US-first campaign that abuses legitimate
RMM software while rapidly rotating domains, lures, and remote access products.
The more durable detection opportunity lies in the delivery framework, recurring kit patterns and
unsolicited RMM installation rather than individual IOCs or product names.
Strengthen your society with any.
RUNS-U-N using any.
Run's interactive sandbox, we expose the full attack chain, from browser activity and redirects
to scripts, processes, and network traffic.
Thread intelligence lookup then turned persistent indicators in Topivets for uncovering
related infrastructure and expanding the investigation across the wider campaign.
About any run.
Any.
Run provides interactive malware and
analysis and threat intelligence solutions to more than 16,000 organizations and 700,000
security professionals worldwide. Its interactive sandbox helps society teams, MSPs, and threat researchers
investigate malware, suspicious files, and urls in controlled virtual environments.
Analysts can observe execution chains, inspect network activity, and uncover malicious behavior
in real time to make faster, more confident decisions. Any run-threat intelligence turns data from
real-world investigations into actionable threat intelligence, helping security teams enrich alerts,
uncover related infrastructure, investigate campaigns, and track evolving threats.
TTPs, tactic technique, ID, description resource development acquire infrastructure, web services,
T1583-006, the operator used 82 one-shot, VERSEL, app deployments, one Netlify app,
and GitHub, I.O. Pages to host the lure kit. Resource development acquire infrastructure.
Domains, T1583.001. The operator registered 32 throwaway domains on cheap TLDs and used seven
dynamic DNS names to serve the same kit. Resource development compromise infrastructure, T1584.
The operator used compromised legitimate websites. Eight confirmed in this arm, one 17 conventional sites family-wide,
to serve the icons 8 Microsoft Word 94 PNG Kitpath initial access fishing spearfishing link
T1566002 the operator used a CRA T4 spearfishing email to link victims TSAW
VERSEL app lure page execution user execution malicious file T124-002 the operator used an on-page
access code to induce the victim to extract and run single VBS script.
Execution command and scripting interpreter.
Visual Basic PowerShell, T-1059.
001.
The VBS script used file system object to launch PowerShell and download the next stage.
Defense evasion obfuscated, encrypted files.
Password protected archive, T-1027.
The kit used a password-protected project, asterisk.
Zip requiring the on-page access code at O block automated extraction, defense evasion
VATUVASION virtualization, sandbox evasion, T1497, the operator used telegram-based victim filtering,
browser, IP, geo-fingerprinting, and sleep timing to evade analysis environments.
Command and control ingress tool transfer, T1105.
The operator used PowerShell to download the RMMMSI from rotating S3, R2, GitHub, Go File,
IP staging. Command and control remote access software, T1219. The operator used a signed RMM
agent to establish hands on keyboard remote access. Go to resolve and log main rescue in this arm,
screen connect and connect wise in sibling arms. Command and control web service, T1102, the kit
use ETP. Telegram, Orgdo filter victims and conditionally deliver the payload, IOCs,
all indicators are defanged, kit handwriting, detection paths.
Patterns.
Asterisk, secure.
HTML on host.
Versel app project, asterisk.
Zip on host.
Versel, app IMG, font 1.
Waf 2.
The family wide font pivot, 425 Earls, 240 hosts.
Per recipient path pattern, FTX.
Less than 6 char slug greater than less than 10 digit epic greater than less than 12 hex greater than, on-in platform hosts.
289 Earls, 110 hosts.
110 hosts. The epic field dates the links generation DOM. Font family. FMTT plus IMG, font 1. Waf2 plus
alt equals PDF icon plus access code as text lure deployments representative. 82 Vurcell apps
observed in total filling confirmation. Versal app shared confirmation slip.
Versel, App official summary by Cray.
Versel, App 2026T4 Form 17,718.
Versel, app Cratac summary 1,7,341.
Versel, app statement details file cinderdurf, netlify, app throwaway domains carrying a
malicious verdict at observation.
Quavix.
Voo Savora, Voo Zorlira, Vue Veretics, I-C-U-Wrhyl, SBS Morixa,
CFD GEDL JORIX, CUPDF March light statements scanned for you. Gixar, SBS reports TASMON for
March review yours SAST. Harnevo, CFD Dynamic DNS Kit hosts, attacker-controlled subdomains of legitimate
DDNS providers, block the host, not the provider. 54511 D-DNS King, Com DXY 43, D DNS King,
D-D-N-S King.
Com 67-P-2.
Me D-Cesh-23.
Swoop to, me-S-I-E-D-N-3.
Let's go to, me-D-N-3.
Net 2 me.
Me captured R.M-M-M-SI.
HX-XPS-C-Colon slash-Commonerdays.
Versel, app.
Log me in Resolve underscore Unattended.
MSI payload staging,
attacker-controlled buckets,
May Tesla Advisor H-HQ.
S3.
East 2, Amazon Oz, Com Open Fodder VBS 4 View, AMS 3, CDN, Digital Ocean Spaces, Com durable origin IP, 462,197, 232 to 7,000 compromised legitimate sites, kit path only, Hilton Head Island deals.
Com Gonzales Haramio Abigados, com My Bcdcdc, CA Torresberger Co, com, OY Patel Law Office,
A electrical say, com Hercules-Calgary Movers, CAQWontec it solutions, com kit page content
hashes, Shaw 256, 41B, 731,279B 1778, a 9F, 578E4 ed 2589 F-4589F-46C4BF 32,7993B,
292,862-19279-a-3EA-3EA1C-41, Lur index page.
132D-864B1919105D-639 EDB-15 billion,249-249-ML102,243EAFDB-0FC-2021EFB-86C-0-490
866F-0, Secure.
HTML-Gate page, 51F0-C-172-C-E-2E-90 ACB-C-O-1C-28-272C-7-7-C-B-4-9407-3-950-1-1-6-1-1-4-1-1-5-1-1-5-1-1-1-4-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1.
icons 8 Microsoft Word 94 PNG asset sources cloudflare cloudforce one
Versel hosted RMM abuse campaign evolves with telegram C2 for victim filtering htttps
colon slash slash www cloudflare com cloud force one research report
Versel hosted RMM abuse campaign evolves with telegram C2 for victim filtering
Kasea, Inki, the Versel incident and the fishing campaigns already hiding in plain sight.
Httpskolon slash www.
Kasea, com, blog, fishing campaigns abusing Versel's free hosting platform.
Cyber armor, cybercriminals abusing Versel to deliver remote access malware.
Htttpskolon slash www.
Cyber armor, tech, blog, threat insight cybercriminals abusing Versel to deliver
remote access malware. Red Canary. The dual-use dilemma. Rethinking detection for remote access
tool abuse. HTTPS-Colns slash-R-Cannery. Com, blog, security operations, RMM detection. Broadcom,
semantic. RMM abuse continues. Malicious log main resolve activity on the rise. HTTPS
C.com.com support, security center, protection bulletin, RMM abuse continues malicious log main resolve
activity on the rise.
Canada Revenue Agency, Recognize a Scam. HTTPS, colon slash www.
Canada, CAN, Revenue Agency, Corporate, Scams Fraud, Recognize Scam.
HTML.
Thank you for listening to this hackernoon story, read by Artifference.
official intelligence. Visit hackernoon.com to read, write, learn and publish.
