Phishing Campaign Uses Fake Documents to Install Remote-Access Tools Across 46 Countries

Summary
ANY.RUN describes a 46-country phishing campaign that uses fake documents, password-protected archives, and scripts to install legitimate RMM software for remote access. The analysis links activity through recurring kit assets and infrastructure.
Key points
- The campaign uses fake tax, government, invoice, shipping, and other document lures; researchers link its activity through recurring kit components.
- The broader campaign spans 46 countries, with 45% of observed activity associated with the United States; the CRA/T4 lure arm is more Canada-focused.
- Victims are directed to disposable or compromised websites, then prompted to enter an access code and run a script from a password-protected ZIP.
- A VBS script launches PowerShell, which downloads and installs legitimate, signed RMM software used to gain hands-on remote access.
- Observed RMM products include GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian; no specific threat actor is identified.
- The operators use rotating hosting, browser and geolocation checks, Telegram-based filtering, and timing delays to hinder analysis and automated detection.
- The article recommends detecting the delivery chain and unexpected RMM installations, and using persistent kit indicators rather than relying only on product names or short-lived domains.
Article Details
- Attack Vectors
- Phishing emails link to disposable document-themed lure pages impersonating organizations such as the Canada Revenue Agency and the US Social Security Administration.
- The lure page redirects to secure.html and delivers a password-protected ZIP after providing an access code to the victim.
- After the victim extracts and runs the VBS script, it launches PowerShell to download and install a legitimate RMM agent for remote access.
- Browser, IP, and geolocation fingerprinting, hCaptcha, a spinner gate, Telegram-based victim filtering, and PowerShell sleep delays are used to limit payload delivery or hinder analysis.
- The campaign uses disposable hosting, compromised websites, and rotating payload-staging infrastructure; the RMM product varies across campaign arms.
- Defensive Notes
- Detect the delivery chain and unauthorized RMM installations or activity rather than relying on a specific RMM product or antivirus verdict.
- Monitor for recurring kit indicators, including the fmtt font and font1.woff2, icons8-microsoft-word-94.png, and the secure.html to project/*.zip delivery sequence.
- Account for password-protected ZIP delivery and victim-provided archive passwords in mail-layer controls and user awareness.
- Inventory approved RMM products and investigate unexpected installations, especially those originating from new hosting domains or compromised websites.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | cevora[.]vu | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | docshared[.]org | Campaign kit host observed for the longest reported period. |
| DOMAIN | electrical-sei[.]com | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | gonzalezjaramilloabogados[.]com | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | herculescalgarymovers[.]ca | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | hiltonheadislanddeals[.]com | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | mornixa[.]cfd | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | mybcdc[.]ca | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | quantechitsolutions[.]com | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | quavix[.]vu | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | taurusburgerco[.]com[.]au | Compromised legitimate site used to serve the campaign kit. |
| DOMAIN | voretix[.]icu | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | wurel[.]sbs | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | xorlira[.]vu | Throwaway campaign domain reported as malicious at observation. |
| DOMAIN | ypatellawoffice[.]ca | Compromised legitimate site used to serve the campaign kit. |
| HOSTNAME | 2026t4form17718[.]vercel[.]app | Disposable Vercel lure host listed among campaign deployments. |
| HOSTNAME | 54511[.]ddnsking[.]com | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | 67pon[.]swoop2[.]me | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | crataxsummary1007341[.]vercel[.]app | Disposable Vercel lure host listed among campaign deployments. |
| HOSTNAME | dashboarduat[.]paynnow[.]com | Campaign kit host that served the most reported kit URLs. |
| HOSTNAME | dcsi23[.]swoop2[.]me | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | ddn3[.]net2me[.]me | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | dxy43[.]ddnsking[.]com | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | dyb32[.]ddnsking[.]com | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | fillingconfirmation[.]vercel[.]app | Disposable Vercel lure host used in the campaign. |
| HOSTNAME | getdl[.]jorix[.]cyou | Throwaway campaign host reported as malicious at observation. |
| HOSTNAME | mayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]com | Attacker-controlled bucket used for payload staging. |
| HOSTNAME | officialsummarybycra[.]vercel[.]app | Disposable Vercel lure host listed among campaign deployments. |
| HOSTNAME | openfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]com | Attacker-controlled bucket used for payload staging. |
| HOSTNAME | pdfmarchlitestatementsscannedforyou[.]gixar[.]sbs | Throwaway campaign host reported as malicious at observation. |
| HOSTNAME | reportstastementformarchreviewyourssaast[.]harnivo[.]cfd | Throwaway campaign host reported as malicious at observation. |
| HOSTNAME | sharedconfirmationslip[.]vercel[.]app | Disposable Vercel lure host listed among campaign deployments. |
| HOSTNAME | ssi11[.]letsgo2[.]me | Attacker-controlled dynamic-DNS host serving the campaign kit. |
| HOSTNAME | statemendetailsfilessenderderf[.]netlify[.]app | Netlify lure host listed among campaign deployments. |
| SHA256 | 132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0 | SHA-256 hash of the campaign secure.html gate page. |
| SHA256 | 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41 | SHA-256 hash of a campaign lure index page. |
| SHA256 | 51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42 | SHA-256 hash of the campaign icons8-microsoft-word-94.png asset used as a family indicator. |
| URL | hxxps[:]//commonerdays[.]vercel[.]app/LogMeInResolve_Unattended[.]msi | Specific campaign URL hosting a captured LogMeIn Resolve installer payload. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationA password-protected ZIP archive impeded automated extraction and inspection.T1059.001 · PowerShellPowerShell downloaded and installed the RMM MSI.T1059.005 · Visual BasicThe VBS script used FileSystemObject to launch the next stage.T1102 · Web ServiceThe kit used api.telegram.org to filter visitors and conditionally deliver payloads.T1105 · Ingress Tool TransferPowerShell downloaded the RMM MSI from rotating staging infrastructure.T1204.002 · Malicious FileVictims were induced to enter an access code, extract the archive, and run its VBS script.T1219 · Remote Access ToolsSigned RMM agents, including GoTo Resolve and LogMeIn Rescue, provided hands-on-keyboard remote access.T1497 · Virtualization/Sandbox EvasionBrowser, IP, and geolocation fingerprinting, victim filtering, and sleep timing were used to hinder analysis.T1566.002 · Spearphishing LinkPhishing emails linked victims to document-themed lure pages.T1583.001 · DomainsThe operator registered throwaway domains and used dynamic-DNS names to serve the kit.T1583.006 · Web ServicesThe operator hosted lure kits on one-shot Vercel deployments, a Netlify app, and GitHub Pages.T1584 · Compromise InfrastructureThe operator used compromised legitimate websites to serve campaign kit content.
People
Products
ConnectWiseSigned RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms GoTo ResolveSigned RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms ITarianSigned RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms LogMeIn RescueSigned RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms ScreenConnectSigned RMM installers abused as remote-access trojans; productsare interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms VercelDisposable Vercel infrastructure rotates rapidly: 94% of 240 observed hosts appeared for only a single day.
Tools
ANY.RUN Interactive SandboxANY.RUN Threat Intelligence LookupIn this analysis, ANY.RUN’s Interactive Sandbox exposed the delivery chain, browser activity, scripts, and network requests, while Threat Intelligence Lookup expanded persistent indicators into the wider campaign.FingerprintJSThe page fingerprints the browser, IP address, and geolocation using FingerprintJS, an hCaptcha challenge, and a “Green Spinner” gate.
Countries
CanadaAs ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries,United Statesremote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States.
Industries
BankingBanking, manufacturing, and finance also feature prominently, aligning more closely with the campaign’s invoice and VAT-themed lures.EducationAcross industries, education, technology, and government appear prominently in both datasets.financeBanking, manufacturing, and finance also feature prominently, aligning more closely with the campaign’s invoice and VAT-themed lures.GovernmentAcross industries, education, technology, and government appear prominently in both datasets.ManufacturingBanking, manufacturing, and finance also feature prominently, aligning more closely with the campaign’s invoice and VAT-themed lures.TechnologyAcross industries, education, technology, and government appear prominently in both datasets.