A sweeping phishing campaign has been uncovered that impacts 46 countries—and the United States is leading the pack as the primary target. Roughly 45% of all observed incidents occurred in the U.S., according to cybersecurity analysts who have tracked over 600 cases tied to the operation. Attackers are using fake documents to trick victims into installing legitimate remote monitoring and management (RMM) tools for malicious access.
What the Campaign Looks Like on the Ground
This extensive campaign was initially linked to Canadian targets, due to the use of false tax forms from the Canada Revenue Agency as lures. However, researchers now believe it’s far more expansive. The threats span multiple sectors—education, tech, government, banking, finance, and manufacturing are among the most impacted. Attackers tailor their decoys to match each target’s region, employing UPS or shipping notices, fake PDFs, invoices, Social Security Administration fonts, and tax-related content to fool users.
How the Attackers Stay Hidden
The infrastructure behind the campaign rotates rapidly. Of the 240 hosts identified, nearly all (94%) were only seen active for a single day. Phishing kits deploy through platforms like Vercel, GitHub Pages, and Netlify, plus trojanized or compromised sites. Payloads are staged via widely-used services, including Amazon S3, Cloudflare R2, DigitalOcean Spaces, Dropbox, and GoFile. This disposable approach makes it tough for defenders to pin down malicious domains.
Even so, analysts found enduring breadcrumbs. Shared assets like a specific font file (font1.woff2), a recurring icon file (icons8-microsoft-word-94.png), and a delivery chain pattern (starting with secure.html and ending with a project/*.zip file) allowed investigators to link disparate attacks. These elements are more reliable than domains, which disappear quickly. Security operations centers (SOCs) emphasize that behavioral context—recognizing how files are moved, scripts run, browsers manipulated—is essential to distinguishing fake RMM activity from legitimate operations.
How Organizations Are Defending Themselves
To combat this churn of infrastructure and persistent abuse, recommendations for defenders include building vendor-agnostic detection pipelines, monitoring for delivery-chain indicators, and enforcing mail-layer controls—especially around password-protected archives. Raising user awareness is also critical, as phishing messages often include files that seem legit but hide RMM installers.
Visibility tools that capture browser behavior, script execution, file downloads, and network connections are proving invaluable. Threat intelligence platforms that connect indicators across multiple incidents are helping to illuminate how campaigns evolve and reuse infrastructure.
As reliance on remote management tools grows, so does the potential for abuse. The combination of trusted services, disposable web infrastructure, and social engineering makes this campaign a particularly challenging threat.
Why It Matters: This campaign shows how attackers are adapting—quick domain rotation, mixed infrastructure, and leveraging legitimate RMM tools to bypass traditional defenses. Organizations must rethink detection strategies to focus on patterns and behavior instead of only known domains. Expect threat intelligence, endpoint visibility, and rigorous email security policies to play a larger role in the fight ahead.