The Good Tech Companies - A Single Canadian Tax Lure Spread into a 46-Country, US-First RMM Campaign

Episode Date: September 1, 2026

This story was originally published on HackerNoon at: https://hackernoon.com/a-single-canadian-tax-lure-spread-into-a-46-country-us-first-rmm-campaign. ANY.RUN uncovers ...a 46-country phishing campaign using fake tax documents, Vercel infrastructure, and legitimate RMM software for remote system access. Check more stories related to undefined at: https://hackernoon.com/c/undefined. You can also check exclusive content about #vercel-phishing-campaign, #rmm-abuse-phishing-campaign, #logmein-rescue-phishing, #ai-threat-intelligence, #legitimate-rmm-software, #remote-access-trojan, #goto-resolve-malware, #good-company, and more. This story was written by: @anyrun. Learn more about this writer by checking @anyrun's about page, and for more stories, please visit hackernoon.com. A phishing campaign disguised as CRA T4 tax documents is part of a broader operation spanning 46 countries, with 45% of observed activity linked to the US. Instead of deploying conventional malware, attackers use legitimate RMM tools such as GoTo Resolve, LogMeIn Rescue, ScreenConnect, and ConnectWise to gain remote access. The campaign rotates Vercel apps, domains, and lures, making delivery-chain and behavioral detection more effective than product-based signatures.

Transcript
Discussion (0)
Starting point is 00:00:00 This audio is presented by Hacker Noon, where anyone can learn anything about any technology. A single Canadian tax lure spread into a 46 country, US-first RMM campaign. By any run, as any, run analysis shows, a campaign that initially appears to target Canadian with fake Canada revenue agency, CRA T4 tax documents is actually part of a much broader remote access campaign spanning 46 countries, with 45% of observed activity associated with the United States. The attackers impersonate trusted organizations and document types to trick victims into installing legitimate remote management software, giving them remote access to compromised systems. Part 1 campaign scope, impact, and defense. Threat overview this fishing operation's final goal
Starting point is 00:00:47 is the remote control of the victim machine. A reusable fake document kit delivers interchangeable, legitimate RMM software installer, which the attacker then abuses for hands own access. Because the Payload assigned commercial software, ordinary signature-based antivirus cannot flag it. Its activity resembles ordinary remote administration. View this malware analysis in TI reports the campaign uses multiple lures, including the U.S. Social Security Administration, Adobe PDF documents, invoices, VAT notices, and shipping communications, allowing the same attack model to target victims across different regions and business contexts. campaign profile attribute assessment threat type fishing delivering RMM as rat for living off
Starting point is 00:01:31 the land remote access family fake document to RMM kit. The CRAT forward lure is one arm of a broader FMTT font-length family severity high, hands-on keyboard remote access sophistication capable, kid-based delivery, Lalbon RMM abuse, password-protected archive, telegram-based victim filtering, built entirely on legitimate signed tooling payload ad sign RMM installers abused as remote access trojans. Products are interchangeable and include GoTo Resolve. Log Main Rescue. Etarian in this arm. Screen ConnectWise in sibling arms impersonated brands Canada Revenue Agency, 2025T4 Form, SSA, VAT, Auto, DocuSign, Adobe PDF, overdue invoices, shipping documents attribution campaign level based on shared delivery kit handwriting,
Starting point is 00:02:20 no-named threat actor. Whether this is one option, or a shared fishing as a service kit remains unknown activity window January 2026 to present. Steady 17 to 33 kit cases per month statistics and victimology two scopes are important here. The CRA T-4ward Arm with 137 observed cases and THE broader fake document family, covering 425 kit URLs across 240 hosts and 601 cases with geographic and industry context. Activity grew from a single observed case in January. January 2026 to a steady 17 to 33 cases per month. Because the final payload is legitimate-signed RMM software, cases are tracked through shared kid assets rather than malware family verdicts,
Starting point is 00:03:06 which would significantly undercount the campaign. Geographically, the broader family is U.S. first, while the CRA T-4 arm is Canada first. North America accounts for 61% of family cases, but activity spans 46 countries, with 35 contributing 1% or less. Canada represents 16% of the broader family but 33.3% of the CRA T4RM, consistent with deliberate targeting around the Canadian tax lure. Across industries, education, technology, and government appear prominently in BOTD datasets. Technology figures may be influenced by higher security team submission rates, while the exposure seen in education and government is more consistent with genuine targeting. Banking, manufacturing, and finance also feature prominently.
Starting point is 00:03:53 aligning more closely with the campaign's invoice and VAT-themed lures. These figures represent where campaign samples were observed rather than-confirmed compromises, so they should be treated as indicators of targeting focus and a proxy for the potential victim population. What to take back to your SOC team for security leaders, the key takeaway is that defenses need to be product agnostic. This campaign abuses legitimate, signed RMM software and can switch between vendors, so controls built around a specific tool or AVU, verdict will leave gaps. Ensure your society focuses on the delivery chain and unauthorized remote access activity instead. Treat the RMM install itself as a signal, whatever the product. GoTo Resolve,
Starting point is 00:04:36 log main rescue, screen connect, connect-wise, and Atari have all been abused in this campaign. Detection should focus on how the software reaches the environment, particularly installations originating from new free hosting domains are compromised WordPress pages, rather than on the RMM product itself. Build detection around persistent campaign patterns, disposable vercell infrastructure rotates rapidly, 94% of 240 observed hosts appeared for only a single day. Instead of relying primarily on domains, prioritize stable kit indicators, including the FMTT, font 1. Waf 2, icons 8 Microsoft Word 94, PNG asset, and the secure HTML right pointing arrow project, asterisk, zip chain, Account for password-protected archive delivery.
Starting point is 00:05:25 The campaign pairs fake document pages with password-protected zip files and provides the password to the victim, helping payloads evade automated inspection. Mail-layer controls and user awareness should account for this delivery pattern. Baseline authorized remote access tooling. Maintain an inventory of approved RMM products and ensure the society can quickly identify unexpected installations or activity. Give analysts behavioral and threat context in one investigation work. In this analysis, any runs interactive sandbox exposed the delivery chain, browser activity,
Starting point is 00:05:59 scripts, and network requests, while threat intelligence look up expanded persistent indicators into the wider campaign. Explore any run for your team part two. Technical malware analysis. Introduction new. Versal app deployments appear more or less constantly, each only day solved. One of them, filling confirmation. Versel app had been registered just one day before it was observed.
Starting point is 00:06:22 reserved. Verselle suits the operator well. Every deployment comes with valid TLS, a trusted domain, and one command redeployment. All this gives the lures the reputation needed to clear mail filters while remaining cheap enough to abandon at will. The activity has continued since January 2026 at a steady monthly pace, with 18 to 57 new kit hosts appearing each month. Cloudflare, Casilla, Inki, and Cyber Armor have also reported on this activity, with findings consistent with what follows here. The delivery chain the attack begins with a phishing email linking to a disposable. Versel app page disguised as a legitimate document. The CRA T4 Lour is one example, alongside SSA, VAT, invoice, shipping, and other document-themed variants. The page redirects to secure HTML,
Starting point is 00:07:14 which provides an access code and downloads a password protected zip, the payload. Once the victim extracts and runs the VBS script inside, power-s, shell downloads and installs a legitimate RMM agent, giving the operator hands on keyboard remote access. The kit's handwriting revealed via advanced URL analysis using any. Runs in browser data inspection, we reconstructed the full browser side chain, including DOM changes, redirects, page content, and screenshots of what the victim sees at each stage. Every deployment ships essentially the same page, byte for byte. Several recurring DOM elements reveal the kit's distinctive handwriting, an empty title. A at Fontface declaration for font family. FMTT. Sourcing URL, IMG, font 1. Waf2. The shared font
Starting point is 00:08:03 that links the broader family. IMGSRC equals IMG, icons 8 Microsoft Word 94. PNG, ID equals, FD, alt equals PDF icon, a word icon persistently mislabeled as PDF icon. A hashtag RL Red Spinner A three-hop meta-refresh chain, root page right-pointing arrow secure. HTML right-pointing arrow project, less than lure greater than. Zip. The recurring, downloading 2025T4 form, and access code text. For additional cover, the kit opens a harmless decoy PDF through legitimate OneDrive infrastructure, 1DRIV.
Starting point is 00:08:45 Ms. OneDrive, Live, Com, and Canada East 1MediaP. SVC. Ms. Its purpose is simply to make the download appear routine to the victim. Execution behavior using static discovering in any. Runs interactive sandbox, we inspected the VBS script responsible for launching the next stage of the attack. The chain progresses only after the victim enters the on-page access code. This unlocks a single VBS script that uses file system object to launch PowerShell. X-Ean download the next stage.
Starting point is 00:09:17 Register with any. RUN-POWShell does the rest. It skips the user profile, introduces a sleep-delay tovade timing-based analysis, writes binary data to a stream, and downloads and installs the RMMMSI. Once installed, the RMM agent gives the operator live, hands-on keyboard access to the system. Evasion Evasion operates across multiple stages of the delivery chain. The first layer is the archive, project, less than lure greater than. Zip returns HTT-T-P-200 but remains password encrypted, leaving auto-eventingerted, leaving
Starting point is 00:09:50 automated pipelines with an inert zip they canotopin. The VBS inside is extracted and executed only after the victim enters Theon page access code. The second layer sits in front of payload delivery. The page fingerprints the browser, IP address, and geolocation using fingerprint JS, an H-C-A-P-T-C-H-A challenge, and a green spinner gate. On some pages, the results are relayed Toopi, Telegram, org, allowing the payload to be served only to visitors that pass the checks while filtering out suspected analysis environments. The PowerShell stage adds timing-based evasion by calling sleep before reaching out for the MSI installer. HTTP request analysis in any runs interactive sandbox made these delivery and evasion flows visible. Following the network
Starting point is 00:10:38 trail revealed a broader, highly distributed infrastructure. Network infrastructure delivery infrastructure, the family includes 82 code identical VERSL apps, each observed for only a single day, alongside GitHub pages, Netlify, compromise legitimate websites, and throwaway domains. Versel is particularly useful to the operator because each new deployment inherits valid TLS and domain reputation. Payload staging. RMM installers are staged across rotating infrastructure, including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, GoFile. I.O. Dropbox, compromised sites, and raw IP hosts. RMM infrastructure, the remote access product is interchangeable. At least five legitimate RMM products have appeared across the family, while the delivery
Starting point is 00:11:28 chain remains largely unchanged. The evidence behind each product is uneven, which bounds what any per product signature can cover. RMM product what backs it install, network artifacts measured LogMe in Rescue, Resolve 46 cases in this arm. Captured MSI LogMe in Resolve underscore unattended. MSI yes. Logme in Rescue Mutex on host go to resolve dominant product by network telemetry in this arm yes, TLS SNI and DNS Togato resolve. Comscreen Connect 204 family cases. Outside this arm identified by case tag connect WISE 106 family cases. Outside this arm identified by case tag I Tarian one case know those measured artifacts cover the go-to and log main slot only. The RMM stage is the thinnest layer of evidence in the chain. 20 of the 137 arm cases are observed fetching the MSI,
Starting point is 00:12:20 while the rest stop at the password protected archive, and the same MSI appears in 150 cases index-wide, SWA is staged across delivery arms beyond this kit. Neither the staging host nor the RMM backend identifies the operator. The MS is its on shared, abused cloud story. and the backend is each vendor's own infrastructure, so neither layer establishes that one operator is behind all OFIT. The delivery kit's handwriting is what ties the activity together. The fact that the product in the RMM slot changes between arms is another reason why this slot is the weakest layer for building a durable signature. Cluster expansion the CRA T-4arm is one part of a broader delivery framework whose document themes, domains, and RMM payloads change while the underlying kit remains stable.
Starting point is 00:13:08 The shared FMTT web font, IMG, font 1. Waf2, provides a particularly strong pivot into that wider activity. Arm how to recognize it payload, behavior cray, T4 Word on Vercelicons 8 Microsoft Word 94. PNG, it equals FD, alt equals PDF icon, plus secure. HTML Plus project, asterisk, zip on, Versel, app. Access code ZIPP password zip to VB, to PowerShell to Go to Resolve, Log Me in Rescue MSI Adobe PDF, SSA, compromised WordPress Siblings same FMTT font 1. Waf2 font, paths, PDF viewer updater, admin, SSAA, WP content, file, screen connect, connect-wise,
Starting point is 00:13:58 other RMM tooling, plus telegram victim filtering to determine whether this is a shared fishing as a service kit with several affiliates, we can use Thread Intelligence Lookup for cluster expansion. URL. Asterisk IMF font 1. Waf 2 inches ORURURL. Asterisk. Icons 8 Microsoft Word 94 PNG, Orsha 256. 51F0 C. 172 C.1 C.27 M.A. 97-E.7 million 64,380E 597,076,350A6B-286 AB-286-N. 7 C.C.B 42 inches. The query returns 601 analysis cases across the three indicators, at the time of writing. The font alone links 425 distinct kit URLs across 240 hosts and 155 IPs between February 5th and July 29, 2026, exposing activity well beyond the CR.
Starting point is 00:15:01 A T-4-arm. The same fingerprint produced no matches across roughly 46,000 cases from 10 unrelated malware families, supporting its use as an operation-specific marker rather than a generic web artifact. Try Ti look up for your S-O-C-I-N-F-R-A-S-T-U-R-E footprint the font 1. Waf2 Query provides a direct measure of the family's delivery infrastructure. Across 174 days, it identified 425 distinct kit UR.A. on 240 hosts resolving to 155 IPs. Measure value distinct kit URL's 425 unique hosts serving the kit 240 unique resolving IPs 155 observation window the 5th of February to the 29th of July 2026.
Starting point is 00:15:49 174 days. Hosts seen within a single day 225 of 240, 94%. Hosts seen over three days or less 228 of 240, 95% longest-lived host doc shared. Org, 23 days busiest host dashboard UAT. Pay N Now, Com, 45 kit URLs in 11. Five days the hosting breakdown shows how this infrastructure is distributed across different host types. Hosting type hosts kit URLs conventional websites, compromised or stood up,
Starting point is 00:16:22 117,257 Versailles. Asterisk. Versel, App 8,282 throwaway registrations on cheap TLDs. VU.S.B.S.C.F.D. I see you. Top.1.CU. Shop. Online. Site. 3,265 dynamic DNS. D DNS King. comm swoop to me let's go to me net to me me 719 netlify asterisk netlify app 11 backblaze b2 f004 backblaze ab to com 11 total 240,4 push button deployment platforms account for 83 of the 240 hosts with vurcell supplying 82 of them every vercell app was observed on exactly one day with exactly one kit URL and was never reused, indicating a one app per lure deployment model that makes domain level blocking quickly
Starting point is 00:17:21 obsolete. Lure theme in the Vercel subdomain apps CRA T4 Techs, 2025 T4 AB 1,109,061, Kratak summary 1,7,341, official summary by Cray, 27 generic shared document, file transfer, shared doc 820,848,10,641, New files shared. 25 invoice, payment, VAT. Invoice 49,883 due. Payment resell PT 8 Adobe, PDF, Flash Updator, Adobe UPD, PDF viewer new, flash updater. 7 streaming, invite, social, live event stream, kick to gather now. 7 USSA, Social Security.
Starting point is 00:18:10 Social Security Statement received 03204 shipping and logistics. UPSAWB 4,290,324, four total 82 new hosts appear at a steady clip, while Vrcell deployments arrive in bursts, 23 new apps in March, at the height of Canadian T4 season, and 20 more in July. Month, 2026, new hosts of which Vercel Apps Kit URLs seen February 18,629 March 432,359 April 451,76, May 4,416, 115 June 33,759 July to 29th, 572087 total 24,082,425. The infrastructure also splits into two distinct URL patterns. All 83 Verselle and Netlify apps serve the kid directly from IMG, font 1. Waf 2, while 110 other hosts use per recipient paths in the form, FTX, less than slug greater
Starting point is 00:19:15 than less than Epic greater than less than hex greater than. The embedded Unix time stamps reveal the campaign's operational tempo. The median link was first observed just 32 minutes after generation, and 77% within 24 hours. This strongly suggests that links are generated per recipient and used almost immediately. Reputation follows the same divide of 425 URLs, 23 were already rated malicious when observed, all hosted on cheap TLD throwaway domains. None were Vercel apps, suggesting that the platform provides the clean domain reputation the operator's own disposable domains lack. Conclusion, this analysis uncovered a 46 country, US-first campaign that abuses legitimate RMM software while rapidly rotating domains, lures, and remote access products.
Starting point is 00:20:05 The more durable detection opportunity lies in the delivery framework, recurring kit patterns and unsolicited RMM installation rather than individual IOCs or product names. Strengthen your society with any. RUNS-U-N using any. Run's interactive sandbox, we expose the full attack chain, from browser activity and redirects to scripts, processes, and network traffic. Thread intelligence lookup then turned persistent indicators in Topivets for uncovering related infrastructure and expanding the investigation across the wider campaign.
Starting point is 00:20:36 About any run. Any. Run provides interactive malware and analysis and threat intelligence solutions to more than 16,000 organizations and 700,000 security professionals worldwide. Its interactive sandbox helps society teams, MSPs, and threat researchers investigate malware, suspicious files, and urls in controlled virtual environments. Analysts can observe execution chains, inspect network activity, and uncover malicious behavior in real time to make faster, more confident decisions. Any run-threat intelligence turns data from
Starting point is 00:21:10 real-world investigations into actionable threat intelligence, helping security teams enrich alerts, uncover related infrastructure, investigate campaigns, and track evolving threats. TTPs, tactic technique, ID, description resource development acquire infrastructure, web services, T1583-006, the operator used 82 one-shot, VERSEL, app deployments, one Netlify app, and GitHub, I.O. Pages to host the lure kit. Resource development acquire infrastructure. Domains, T1583.001. The operator registered 32 throwaway domains on cheap TLDs and used seven dynamic DNS names to serve the same kit. Resource development compromise infrastructure, T1584. The operator used compromised legitimate websites. Eight confirmed in this arm, one 17 conventional sites family-wide,
Starting point is 00:22:06 to serve the icons 8 Microsoft Word 94 PNG Kitpath initial access fishing spearfishing link T1566002 the operator used a CRA T4 spearfishing email to link victims TSAW VERSEL app lure page execution user execution malicious file T124-002 the operator used an on-page access code to induce the victim to extract and run single VBS script. Execution command and scripting interpreter. Visual Basic PowerShell, T-1059. 001. The VBS script used file system object to launch PowerShell and download the next stage.
Starting point is 00:22:52 Defense evasion obfuscated, encrypted files. Password protected archive, T-1027. The kit used a password-protected project, asterisk. Zip requiring the on-page access code at O block automated extraction, defense evasion VATUVASION virtualization, sandbox evasion, T1497, the operator used telegram-based victim filtering, browser, IP, geo-fingerprinting, and sleep timing to evade analysis environments. Command and control ingress tool transfer, T1105. The operator used PowerShell to download the RMMMSI from rotating S3, R2, GitHub, Go File,
Starting point is 00:23:31 IP staging. Command and control remote access software, T1219. The operator used a signed RMM agent to establish hands on keyboard remote access. Go to resolve and log main rescue in this arm, screen connect and connect wise in sibling arms. Command and control web service, T1102, the kit use ETP. Telegram, Orgdo filter victims and conditionally deliver the payload, IOCs, all indicators are defanged, kit handwriting, detection paths. Patterns. Asterisk, secure. HTML on host.
Starting point is 00:24:05 Versel app project, asterisk. Zip on host. Versel, app IMG, font 1. Waf 2. The family wide font pivot, 425 Earls, 240 hosts. Per recipient path pattern, FTX. Less than 6 char slug greater than less than 10 digit epic greater than less than 12 hex greater than, on-in platform hosts. 289 Earls, 110 hosts.
Starting point is 00:24:30 110 hosts. The epic field dates the links generation DOM. Font family. FMTT plus IMG, font 1. Waf2 plus alt equals PDF icon plus access code as text lure deployments representative. 82 Vurcell apps observed in total filling confirmation. Versal app shared confirmation slip. Versel, App official summary by Cray. Versel, App 2026T4 Form 17,718. Versel, app Cratac summary 1,7,341. Versel, app statement details file cinderdurf, netlify, app throwaway domains carrying a malicious verdict at observation.
Starting point is 00:25:15 Quavix. Voo Savora, Voo Zorlira, Vue Veretics, I-C-U-Wrhyl, SBS Morixa, CFD GEDL JORIX, CUPDF March light statements scanned for you. Gixar, SBS reports TASMON for March review yours SAST. Harnevo, CFD Dynamic DNS Kit hosts, attacker-controlled subdomains of legitimate DDNS providers, block the host, not the provider. 54511 D-DNS King, Com DXY 43, D DNS King, D-D-N-S King. Com 67-P-2. Me D-Cesh-23.
Starting point is 00:25:59 Swoop to, me-S-I-E-D-N-3. Let's go to, me-D-N-3. Net 2 me. Me captured R.M-M-M-SI. HX-XPS-C-Colon slash-Commonerdays. Versel, app. Log me in Resolve underscore Unattended. MSI payload staging,
Starting point is 00:26:17 attacker-controlled buckets, May Tesla Advisor H-HQ. S3. East 2, Amazon Oz, Com Open Fodder VBS 4 View, AMS 3, CDN, Digital Ocean Spaces, Com durable origin IP, 462,197, 232 to 7,000 compromised legitimate sites, kit path only, Hilton Head Island deals. Com Gonzales Haramio Abigados, com My Bcdcdc, CA Torresberger Co, com, OY Patel Law Office, A electrical say, com Hercules-Calgary Movers, CAQWontec it solutions, com kit page content hashes, Shaw 256, 41B, 731,279B 1778, a 9F, 578E4 ed 2589 F-4589F-46C4BF 32,7993B, 292,862-19279-a-3EA-3EA1C-41, Lur index page.
Starting point is 00:27:25 132D-864B1919105D-639 EDB-15 billion,249-249-ML102,243EAFDB-0FC-2021EFB-86C-0-490 866F-0, Secure. HTML-Gate page, 51F0-C-172-C-E-2E-90 ACB-C-O-1C-28-272C-7-7-C-B-4-9407-3-950-1-1-6-1-1-4-1-1-5-1-1-5-1-1-1-4-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1-1. icons 8 Microsoft Word 94 PNG asset sources cloudflare cloudforce one Versel hosted RMM abuse campaign evolves with telegram C2 for victim filtering htttps colon slash slash www cloudflare com cloud force one research report Versel hosted RMM abuse campaign evolves with telegram C2 for victim filtering Kasea, Inki, the Versel incident and the fishing campaigns already hiding in plain sight.
Starting point is 00:28:44 Httpskolon slash www. Kasea, com, blog, fishing campaigns abusing Versel's free hosting platform. Cyber armor, cybercriminals abusing Versel to deliver remote access malware. Htttpskolon slash www. Cyber armor, tech, blog, threat insight cybercriminals abusing Versel to deliver remote access malware. Red Canary. The dual-use dilemma. Rethinking detection for remote access tool abuse. HTTPS-Colns slash-R-Cannery. Com, blog, security operations, RMM detection. Broadcom, semantic. RMM abuse continues. Malicious log main resolve activity on the rise. HTTPS
Starting point is 00:29:31 C.com.com support, security center, protection bulletin, RMM abuse continues malicious log main resolve activity on the rise. Canada Revenue Agency, Recognize a Scam. HTTPS, colon slash www. Canada, CAN, Revenue Agency, Corporate, Scams Fraud, Recognize Scam. HTML. Thank you for listening to this hackernoon story, read by Artifference. official intelligence. Visit hackernoon.com to read, write, learn and publish.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.