RMM Phish Uses Tax & UPS Lures in 46 Countries

The Hacker News · Medium sophistication
Last updated September 3, 2026

Researchers describe a real phishing operation that tricks people into installing legitimate remote monitoring and management (RMM) tools so attackers can remotely control devices. The campaign uses familiar-looking documents (tax forms, UPS/shipping notices, Adobe PDFs, invoices, and Social Security themes) and rapidly rotates its hosting infrastructure daily to evade detection.

Key findings

  • The campaign spans 46 countries, with the U.S. as the top target (~45% of observed activity).
  • Lures are tailored by region/theme (tax notices, shipping/UPS messages, invoices, Social Security themes, and Adobe PDF-related pages).
  • The goal is to trick victims into installing legitimate RMM software for remote access.
  • Infrastructure rotates quickly (most kit URLs seen for a single day), but the kit shows repeatable patterns (assets and a consistent delivery chain).
  • Education, technology, and government are among the most targeted industries; banking/finance and manufacturing are also affected.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance/Accounts Payable, Payroll/HR, Administrative staff, IT support/SOC (for reporting and rapid triage).
  • Affected industries: Education, Technology, Government, Banking and finance, Manufacturing.
  • Attack channels: email, website.
  • Impersonated: Canada Revenue Agency (CRA) / UPS / U.S. Social Security Administration (theme varies by target).

Awareness takeaways

  • Treat unexpected “official document” emails (tax, shipping, invoices) as high risk, verify through a known, trusted channel before downloading anything.
  • Be suspicious when a “document” request leads to downloading a ZIP or installer, real agencies and shippers rarely require you to install remote-access tools to view a form.
  • Don’t rely on recognizing a single domain as safe or unsafe; attackers can rotate hosting daily, focus on the behavior (unexpected downloads, remote-access installs).

Red flags to watch for

  • Unexpected “official” document notice pushing you to download/run something
  • Link leads to a hosted page used only briefly (disposable infrastructure)
  • Download flow uses an unusual chain ending in a ZIP (not a normal PDF-only workflow)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Action required: tax document available for download.” Looks like CRA, UPS, or Social Security. You click. The link opens a fake document page that looks like Adobe or UPS, but the download is a ZIP file that quietly installs real remote monitoring software, RMM, so someone can control your machine. Here’s the twist: this campaign hits 46 countries and rotates websites daily, so the URL might look new or harmless. The real red flag is the behavior: an “official” tax or UPS email that makes you download and run a ZIP or installer just to see a form. If any “official document” email wants you to download a ZIP or install anything, stop. Don’t open it, forward it to the security team and confirm through the real CRA, UPS, or agency site instead.

Similar attacks

Fake DocuSign Flow Tricks Users Into RMM Installs

Fake DocuSign Flow Tricks Users Into RMM Installs

Researchers found a DocuSign lookalike phishing workflow that guides people through a realistic “document viewing” experience and then convinces them to download legitimate remote access tools. Instead of classic malware, the attackers install trusted IT administration software (RMM) to keep…

July 20, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Cloudflare Workers Used to Steal MFA Sessions

Cloudflare Workers Used to Steal MFA Sessions

A real multi-stage phishing campaign abused trusted cloud platforms (notably Cloudflare Workers) to make fake login flows look legitimate and to bypass MFA. The attack chained a phishing email, a fake CAPTCHA page on a compromised site, and a browser “pop-up” spoof that captured both credentials…

August 4, 2026
Insurance Phish Turns OTPs Into Live Account Hijacks

Insurance Phish Turns OTPs Into Live Account Hijacks

Researchers observed insurance-themed phishing that doesn’t just steal passwords, it hijacks accounts in real time while the victim is actively logging in. The attack often starts with sponsored Google ads that lead to convincing fake insurance portals, which immediately prompt victims for one-time…

July 25, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026