Researchers describe a real phishing operation that tricks people into installing legitimate remote monitoring and management (RMM) tools so attackers can remotely control devices. The campaign uses familiar-looking documents (tax forms, UPS/shipping notices, Adobe PDFs, invoices, and Social Security themes) and rapidly rotates its hosting infrastructure daily to evade detection.
Key findings
- The campaign spans 46 countries, with the U.S. as the top target (~45% of observed activity).
- Lures are tailored by region/theme (tax notices, shipping/UPS messages, invoices, Social Security themes, and Adobe PDF-related pages).
- The goal is to trick victims into installing legitimate RMM software for remote access.
- Infrastructure rotates quickly (most kit URLs seen for a single day), but the kit shows repeatable patterns (assets and a consistent delivery chain).
- Education, technology, and government are among the most targeted industries; banking/finance and manufacturing are also affected.
Who’s being targeted
- Commonly targeted roles: All employees, Finance/Accounts Payable, Payroll/HR, Administrative staff, IT support/SOC (for reporting and rapid triage).
- Affected industries: Education, Technology, Government, Banking and finance, Manufacturing.
- Attack channels: email, website.
- Impersonated: Canada Revenue Agency (CRA) / UPS / U.S. Social Security Administration (theme varies by target).
Awareness takeaways
- Treat unexpected “official document” emails (tax, shipping, invoices) as high risk, verify through a known, trusted channel before downloading anything.
- Be suspicious when a “document” request leads to downloading a ZIP or installer, real agencies and shippers rarely require you to install remote-access tools to view a form.
- Don’t rely on recognizing a single domain as safe or unsafe; attackers can rotate hosting daily, focus on the behavior (unexpected downloads, remote-access installs).
Red flags to watch for
- Unexpected “official” document notice pushing you to download/run something
- Link leads to a hosted page used only briefly (disposable infrastructure)
- Download flow uses an unusual chain ending in a ZIP (not a normal PDF-only workflow)
Read the video transcript
You get an email: “Action required: tax document available for download.” Looks like CRA, UPS, or Social Security. You click. The link opens a fake document page that looks like Adobe or UPS, but the download is a ZIP file that quietly installs real remote monitoring software, RMM, so someone can control your machine. Here’s the twist: this campaign hits 46 countries and rotates websites daily, so the URL might look new or harmless. The real red flag is the behavior: an “official” tax or UPS email that makes you download and run a ZIP or installer just to see a form. If any “official document” email wants you to download a ZIP or install anything, stop. Don’t open it, forward it to the security team and confirm through the real CRA, UPS, or agency site instead.