Phishing Campaign Uses Fake Documents to Install Remote-Access Tools Across 46 Countries

· Original article ↗

Summary

ANY.RUN describes a 46-country phishing campaign that uses fake documents, password-protected archives, and scripts to install legitimate RMM software for remote access. The analysis links activity through recurring kit assets and infrastructure.

Key points

  • The campaign uses fake tax, government, invoice, shipping, and other document lures; researchers link its activity through recurring kit components.
  • The broader campaign spans 46 countries, with 45% of observed activity associated with the United States; the CRA/T4 lure arm is more Canada-focused.
  • Victims are directed to disposable or compromised websites, then prompted to enter an access code and run a script from a password-protected ZIP.
  • A VBS script launches PowerShell, which downloads and installs legitimate, signed RMM software used to gain hands-on remote access.
  • Observed RMM products include GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian; no specific threat actor is identified.
  • The operators use rotating hosting, browser and geolocation checks, Telegram-based filtering, and timing delays to hinder analysis and automated detection.
  • The article recommends detecting the delivery chain and unexpected RMM installations, and using persistent kit indicators rather than relying only on product names or short-lived domains.

Article Details

Attack Vectors
  • Phishing emails link to disposable document-themed lure pages impersonating organizations such as the Canada Revenue Agency and the US Social Security Administration.
  • The lure page redirects to secure.html and delivers a password-protected ZIP after providing an access code to the victim.
  • After the victim extracts and runs the VBS script, it launches PowerShell to download and install a legitimate RMM agent for remote access.
  • Browser, IP, and geolocation fingerprinting, hCaptcha, a spinner gate, Telegram-based victim filtering, and PowerShell sleep delays are used to limit payload delivery or hinder analysis.
  • The campaign uses disposable hosting, compromised websites, and rotating payload-staging infrastructure; the RMM product varies across campaign arms.
Defensive Notes
  • Detect the delivery chain and unauthorized RMM installations or activity rather than relying on a specific RMM product or antivirus verdict.
  • Monitor for recurring kit indicators, including the fmtt font and font1.woff2, icons8-microsoft-word-94.png, and the secure.html to project/*.zip delivery sequence.
  • Account for password-protected ZIP delivery and victim-provided archive passwords in mail-layer controls and user awareness.
  • Inventory approved RMM products and investigate unexpected installations, especially those originating from new hosting domains or compromised websites.

Indicators of compromise

TypeIndicatorContext
DOMAINcevora[.]vuThrowaway campaign domain reported as malicious at observation.
DOMAINdocshared[.]orgCampaign kit host observed for the longest reported period.
DOMAINelectrical-sei[.]comCompromised legitimate site used to serve the campaign kit.
DOMAINgonzalezjaramilloabogados[.]comCompromised legitimate site used to serve the campaign kit.
DOMAINherculescalgarymovers[.]caCompromised legitimate site used to serve the campaign kit.
DOMAINhiltonheadislanddeals[.]comCompromised legitimate site used to serve the campaign kit.
DOMAINmornixa[.]cfdThrowaway campaign domain reported as malicious at observation.
DOMAINmybcdc[.]caCompromised legitimate site used to serve the campaign kit.
DOMAINquantechitsolutions[.]comCompromised legitimate site used to serve the campaign kit.
DOMAINquavix[.]vuThrowaway campaign domain reported as malicious at observation.
DOMAINtaurusburgerco[.]com[.]auCompromised legitimate site used to serve the campaign kit.
DOMAINvoretix[.]icuThrowaway campaign domain reported as malicious at observation.
DOMAINwurel[.]sbsThrowaway campaign domain reported as malicious at observation.
DOMAINxorlira[.]vuThrowaway campaign domain reported as malicious at observation.
DOMAINypatellawoffice[.]caCompromised legitimate site used to serve the campaign kit.
HOSTNAME2026t4form17718[.]vercel[.]appDisposable Vercel lure host listed among campaign deployments.
HOSTNAME54511[.]ddnsking[.]comAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAME67pon[.]swoop2[.]meAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEcrataxsummary1007341[.]vercel[.]appDisposable Vercel lure host listed among campaign deployments.
HOSTNAMEdashboarduat[.]paynnow[.]comCampaign kit host that served the most reported kit URLs.
HOSTNAMEdcsi23[.]swoop2[.]meAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEddn3[.]net2me[.]meAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEdxy43[.]ddnsking[.]comAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEdyb32[.]ddnsking[.]comAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEfillingconfirmation[.]vercel[.]appDisposable Vercel lure host used in the campaign.
HOSTNAMEgetdl[.]jorix[.]cyouThrowaway campaign host reported as malicious at observation.
HOSTNAMEmayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]comAttacker-controlled bucket used for payload staging.
HOSTNAMEofficialsummarybycra[.]vercel[.]appDisposable Vercel lure host listed among campaign deployments.
HOSTNAMEopenfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]comAttacker-controlled bucket used for payload staging.
HOSTNAMEpdfmarchlitestatementsscannedforyou[.]gixar[.]sbsThrowaway campaign host reported as malicious at observation.
HOSTNAMEreportstastementformarchreviewyourssaast[.]harnivo[.]cfdThrowaway campaign host reported as malicious at observation.
HOSTNAMEsharedconfirmationslip[.]vercel[.]appDisposable Vercel lure host listed among campaign deployments.
HOSTNAMEssi11[.]letsgo2[.]meAttacker-controlled dynamic-DNS host serving the campaign kit.
HOSTNAMEstatemendetailsfilessenderderf[.]netlify[.]appNetlify lure host listed among campaign deployments.
SHA256132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0SHA-256 hash of the campaign secure.html gate page.
SHA25641b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41SHA-256 hash of a campaign lure index page.
SHA25651f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42SHA-256 hash of the campaign icons8-microsoft-word-94.png asset used as a family indicator.
URLhxxps[:]//commonerdays[.]vercel[.]app/LogMeInResolve_Unattended[.]msiSpecific campaign URL hosting a captured LogMeIn Resolve installer payload.

MITRE ATT&CK

People

Products

Tools

Countries

Industries

Related Articles