Global Phishing Campaign Abuses Remote Access Tools — US Now the Top Target
Security researchers have found that a phishing operation originally believed to focus on Canadian businesses—using fake Canada Revenue Agency tax forms as bait—is actually a much larger, global campaign. Analysis from ANY.RUN linked 601 cases to this operation across 46 countries, with the United States accounting for roughly 45% of observed activity, making it the top target ahead of Canada.
The campaign relies on phishing lures to trick victims into installing legitimate Remote Monitoring and Management (RMM) software. Because these tools are widely used by IT teams for everyday support, attackers can exploit them to gain remote access to a victim's systems without triggering the same alarms as traditional malware. Once installed, this access can be used to steal data, deploy further malicious tools, or move deeper into a network.
While this particular campaign began with tax-themed lures, its geographic spread shows attackers are adapting their bait to fit different regions and industries. Businesses of all sizes should treat unexpected requests to install remote access or monitoring software with suspicion, regardless of how official the accompanying documents appear.