Tax & Invoice Phish Push Legit RMM in 46 Countries

eSecurity Planet · Medium sophistication
Last updated August 28, 2026

Researchers reported a real phishing operation spanning 46 countries that tricks people into installing legitimate remote monitoring and management (RMM) tools, giving attackers remote access that can look like normal IT activity. The lures use familiar business themes (tax documents, invoices, shipping notices, DocuSign) and sometimes arrive as password-protected ZIP files that run scripts to download the RMM software.

Key findings

  • A newly documented RMM phishing campaign was observed in 46 countries, with ~45% of activity tied to the United States (per ANY.RUN).
  • Attackers use business-themed lures (tax documents, invoices, shipping notices, DocuSign) to convince users to install legitimate remote-management software.
  • Some messages deliver password-protected ZIP files containing VBS scripts that start PowerShell to download legitimate RMM tools.
  • The campaign used large amounts of short-lived phishing infrastructure: 425 phishing-kit URLs across 240 hosts, and 94% of hosts appeared for only one day.
  • MITRE maps this behavior to Remote Desktop Software (T1219.002), reflecting abuse of legitimate remote support applications for control.

Who’s being targeted

  • Commonly targeted roles: Finance (AP/AR), HR/Payroll, Operations, Sales and Legal (DocuSign users), All employees (general phishing awareness), IT and Service Desk.
  • Affected industries: Professional services, IT and managed service providers (MSPs), General business (cross-industry).
  • Attack channels: email.
  • Impersonated: Tax agency or Social Security, Vendor billing department or shipping company, DocuSign.

Awareness takeaways

  • Treat unexpected tax, invoice, shipping, and e-signature messages as high-risk, especially if they include ZIP attachments or ask you to run anything to view a document.
  • A ‘legitimate tool’ can still be part of an attack, report any unexpected remote-access or IT management software prompts immediately.
  • Keep a clear list of approved remote-access tools and who is allowed to use them; fewer tools makes suspicious activity easier to spot.
  • Don’t rely only on blocking bad links, attackers can rotate infrastructure quickly; focus on inventory, monitoring, segmentation, and rehearsed response.

Red flags to watch for

  • Unexpected password-protected ZIP attachment
  • Script-based attachment (VBS) tied to a 'document' theme
  • Request to run/enable content to view a supposed tax notice
  • Unsolicited invoice or shipping notice
  • Attachment requires running scripts or unusual steps to view
  • Remote-access tool appears on a system where it is not normally used
  • DocuSign request you were not expecting
  • Business workflow used to introduce remote-admin software
  • New remote sessions or remote-access software on non-IT endpoints
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email: “Tax Document, Action Required (Password-Protected ZIP).” Looks official, right? In a real campaign across 46 countries, that ZIP hid a VBS script that fired up PowerShell and quietly installed legit remote monitoring tools, exactly what IT uses, but now under someone else’s control. The lure looks boringly normal: fake tax notices, invoices, shipping updates, even DocuSign. The giveaway isn’t the logo, it’s the ask: a password-protected ZIP and a script you have to run just to “view” a document. If you ever see a tax, invoice, shipping, or DocuSign email that wants you to open a password-protected ZIP or run anything, stop and forward it to Security, do not open the ZIP.

Similar attacks

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026
TA488 “Half-Click” Email Triggers OWA Exploit

TA488 “Half-Click” Email Triggers OWA Exploit

Researchers reported a real TA488 campaign where a specially crafted email exploits an Outlook Web Access (OWA) flaw and runs malicious JavaScript as soon as the user opens the message. The attack relies on normal-looking business topics to get people to quickly view the email, and then uses…

July 30, 2026
Korea APTs Push LNK “Resume” Spear‑Phish

Korea APTs Push LNK “Resume” Spear‑Phish

AhnLab reports that many APT attacks targeting organizations in South Korea in July 2026 started with spear‑phishing emails that delivered malicious Windows shortcut (LNK) files disguised as legitimate documents (including resumes). When opened, the LNK runs scripts that install…

August 28, 2026
Voucher Lure Drops RAT via FTP Banner Tricks

Voucher Lure Drops RAT via FTP Banner Tricks

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads,…

August 25, 2026
Fake Bank of America Email Pushes Remote Access Tool

Fake Bank of America Email Pushes Remote Access Tool

Cybercriminals sent emails styled like Bank of America that redirected victims to fake pages and pushed a download called “Account Guard.” On Windows, the download installed ScreenConnect remote management software, giving attackers remote control of the device. The campaign used lookalike domains…

August 5, 2026