A phishing operation is abusing legitimate remote monitoring and management tools to give attackers direct control over victim systems.
The campaign uses convincing document lures, rapidly changing hosting infrastructure, and signed software that can blend into normal IT activity.
A phishing campaign is turning familiar support software into a direct route into corporate systems. Rather than dropping a clearly malicious program, the operators persuade recipients to install legitimate remote monitoring and management, or RMM, tools that can give an outsider control of a computer.
The activity began with fake Canada Revenue Agency T4 tax documents, but its reach is far broader. The same document-delivery framework has used Social Security Administration notices, Adobe PDF prompts, invoices, VAT alerts, shipping messages, and shared-file themes to target victims across 46 countries.
Analysts at ANY.RUN identified the operation as a US-first campaign, with 45% of observed activity tied to the United States.
ANY.RUN said in a report shared with Cyber Security News (CSN) that North America represented 61% of observed family cases, while the figures indicate targeting rather than confirmed breaches.
The danger lies in the choice of payload. Signed remote-support software can look like normal administrative activity and may not trigger security products built to find known malware.
Once installed, it gives an attacker hands-on access that can be used to browse systems, run commands, or prepare a deeper intrusion.
The campaign has remained active since January 2026, and the researchers caution that observed samples likely understate its true reach.
The attack starts with an email that points to a short-lived page hosted on a trusted cloud platform or a compromised website. A tax form is only one lure.
The page resembles a document portal, gives the recipient an access code, and offers a password-protected ZIP archive that is harder for automated mail scanners to inspect.
After the victim extracts the archive and runs its Visual Basic script, PowerShell fetches an RMM installer. The campaign has used GoTo Resolve and LogMeIn Rescue in this arm, while related activity has used ScreenConnect, ConnectWise, and ITarian.
This flexible approach resembles previous LogMeIn Resolve abuse, where legitimate remote tools were configured for attacker-controlled access.
.webp)
The operator adds several checks before serving the final stage. Browser and location details are collected, an hCaptcha challenge may appear, and some pages send information to Telegram to filter visitors.
A short delay before the download also makes automated analysis less useful, while a harmless online PDF may open to keep the victim focused on the supposed document.
Researchers recorded 425 kit URLs across 240 hosts between February 5 and July 29, 2026. Ninety-four percent of the hosts appeared for only one day, including 82 one-use Vercel applications.
.webp)
The rapid churn reinforces findings from earlier Vercel phishing delivery, where platform reputation can help malicious links get past initial scrutiny.
Blocking a single RMM product or a handful of domains will not reliably stop this campaign because both can change quickly.
Defenders should treat an unexpected RMM installation as an alert, particularly when it follows a download from a new hosting page, a password-protected archive, or a script launched by a user from an unusual location.
Security teams should maintain an approved inventory of remote-access products and investigate any installation outside that list. Email controls and staff awareness training should explicitly cover access-code pages and password-protected ZIP files.
The advice aligns with guidance on several abused RMM tools, which stresses allowlists and attention to unusual execution paths.
.webp)
Hunting should prioritize recurring components of the delivery kit and the page-to-archive flow, instead of relying only on disposable domains.
Reviewing PowerShell activity that downloads MSI files and correlating it with newly installed support software can reveal an intrusion before remote control is used more widely. It also helps teams recognize abuse even when a familiar application carries a valid signature.
That distinction matters for organizations in education, technology, government, banking, manufacturing, and finance, which appeared prominently in the observed data.
Employees should verify tax, invoice, and document requests through an independently known channel, not the link in an email, a lesson also reflected in finance-themed Vercel lures.
Indicators of comrpomise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Detection pattern | */secure.html on *.vercel[.]app | Campaign kit page pattern |
| Detection pattern | */project/*.zip on *.vercel[.]app | Password-protected archive delivery pattern |
| File path | *img/font1.woff2 | Shared web-font pivot associated with the wider campaign |
| URL pattern | /ftx/<6-char slug>-<10-digit epoch>-<12-hex>/ | Per-recipient path pattern on platform hosts |
| DOM pattern | font-family:'fmtt', img/font1.woff2, alt="PDF Icon", Access code | Repeated phishing-kit page elements |
| Domain | fillingconfirmation[.]vercel[.]app | Representative lure deployment |
| Domain | sharedconfirmationslip[.]vercel[.]app | Representative lure deployment |
| Domain | officialsummarybycra[.]vercel[.]app | Representative lure deployment |
| Domain | 2026t4form17718[.]vercel[.]app | Representative lure deployment |
| Domain | crataxsummary1007341[.]vercel[.]app | Representative lure deployment |
| Domain | statemendetailsfilessenderderf[.]netlify[.]app | Representative lure deployment |
| Domain | quavix[.]vu | Throwaway domain with a malicious verdict at observation |
| Domain | cevora[.]vu | Throwaway domain with a malicious verdict at observation |
| Domain | xorlira[.]vu | Throwaway domain with a malicious verdict at observation |
| Domain | voretix[.]icu | Throwaway domain with a malicious verdict at observation |
| Domain | wurel[.]sbs | Throwaway domain with a malicious verdict at observation |
| Domain | mornixa[.]cfd | Throwaway domain with a malicious verdict at observation |
| Domain | getdl[.]jorix[.]cyou | Throwaway domain with a malicious verdict at observation |
| Domain | pdfmarchlitestatementsscannedforyou[.]gixar[.]sbs | Throwaway domain with a malicious verdict at observation |
| Domain | reportstastementformarchreviewyourssaast[.]harnivo[.]cfd | Throwaway domain with a malicious verdict at observation |
| Dynamic DNS host | 54511[.]ddnsking[.]com | Attacker-controlled kit host |
| Dynamic DNS host | dxy43[.]ddnsking[.]com | Attacker-controlled kit host |
| Dynamic DNS host | dyb32[.]ddnsking[.]com | Attacker-controlled kit host |
| Dynamic DNS host | 67pon[.]swoop2[.]me | Attacker-controlled kit host |
| Dynamic DNS host | dcsi23[.]swoop2[.]me | Attacker-controlled kit host |
| Dynamic DNS host | ssi11[.]letsgo2[.]me | Attacker-controlled kit host |
| Dynamic DNS host | ddn3[.]net2me[.]me | Attacker-controlled kit host |
| URL | hxxps://commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msi | Captured RMM MSI download |
| Domain | mayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]com | Payload-staging bucket |
| Domain | openfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]com | Payload-staging bucket |
| IP address and port | 46.62.197[.]232:7000 | Durable origin infrastructure |
| Domain | hiltonheadislanddeals[.]com | Compromised site serving kit path |
| Domain | gonzalezjaramilloabogados[.]com | Compromised site serving kit path |
| Domain | mybcdc[.]ca | Compromised site serving kit path |
| Domain | taurusburgerco[.]com[.]au | Compromised site serving kit path |
| Domain | ypatellawoffice[.]ca | Compromised site serving kit path |
| Domain | electrical-sei[.]com | Compromised site serving kit path |
| Domain | herculescalgarymovers[.]ca | Compromised site serving kit path |
| Domain | quantechitsolutions[.]com | Compromised site serving kit path |
| SHA-256 | 41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead | Lure index-page content hash |
| SHA-256 | 132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d498 | secure.html gate-page content hash |
| SHA-256 | 51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7 | Word-style image asset content hash |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

