As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States.
The attackers impersonate trusted organizations and document types to trick victims into installing legitimate remote management software, giving them remote access to compromised systems.
This phishing operation's final goal is the remote control of the victim's machine. A reusable fake-document kit delivers interchangeable, legitimate RMM software installer, which the attacker then abuses for hands-on access.
Because the payload is signed commercial software, ordinary signature-based antivirus cannot flag it. Its activity resembles ordinary remote administration.
The campaign uses multiple lures, including the US Social Security Administration, Adobe PDF documents, invoices, VAT notices, and shipping communications, allowing the same attack model to target victims across different regions and business contexts.
Campaign Profile
| Attribute | Assessment |
|---|---|
| Threat type | Phishing delivering RMM-as-RAT for living-off-the-land remote access |
| Family | Fake-document-to-RMM kit; the CRA/T4 Word lure is one arm of a broader fmtt font-linked family |
| Severity | High — hands-on-keyboard remote access |
| Sophistication | Capable — kit-based delivery, LOLBin RMM abuse, password-protected archive, Telegram-based victim filtering; built entirely on legitimate signed tooling |
| Payload | Signed RMM installers abused as remote-access trojans; products are interchangeable and include GoTo Resolve, LogMeIn Rescue, ITarian in this arm; ScreenConnect, ConnectWise in sibling arms |
| Impersonated brands | Canada Revenue Agency / 2025 T4 Form, SSA, VAT/ATO, DocuSign, Adobe PDF, overdue invoices, shipping documents |
| Attribution | Campaign-level based on shared delivery-kit handwriting; no named threat actor. Whether this is one operator or a shared phishing-as-a-service kit remains unknown |
| Activity window | January 2026 to present; steady 17–33 kit cases per month |
Two scopes are important here: the CRA/T4 Word arm, with 137 observed cases, and the broader fake-document family, covering 425 kit URLs across 240 hosts and 601 cases with geographic and industry context.
Activity grew from a single observed case in January 2026 to a steady 17–33 cases per month. Because the final payload is legitimate signed RMM software, cases are tracked through shared kit assets rather than malware-family verdicts, which would significantly undercount the campaign.
| Month | Kit cases |
|---|---|
| 2026-01 | 1 |
| 2026-02 | 17 |
| 2026-03 | 33 |
| 2026-04 | 22 |
| 2026-05 | 20 |
| 2026-06 | 21 |
| 2026-07 (to the 17th) | 23 |
| Total | 137 |

Figure 1. Kit cases per month
Geographically, the broader family is US-first, while the CRA/T4 arm is Canada-first. North America accounts for 61% of family cases, but activity spans 46 countries, with 35 contributing 1% or less. Canada represents 16% of the broader family but 33.3% of the CRA/T4 arm, consistent with deliberate targeting around the Canadian tax lure.
| Country | Family (601 cases) | CRA/T4 arm (137 cases) |
|---|---|---|
| United States | 45% | 31.8% |
| Canada | 16% | 33.3% |
| India | 10% | 4.7% |
| Korea, Republic of | 4% | 2.3% |
| Egypt | 2% | — |
| Kazakhstan | 2% | — |
| Philippines | 2% | — |
| Australia | 2% | 1.6% |
| United Kingdom | 2% | 0.8% |
| United Arab Emirates | 2% | — |
| Mexico | 2% | — |
| Israel | 0.5% | 1.6% |
| Pakistan | 0.3% | 1.6% |
| Saudi Arabia | 0.3% | 0.8% |
| Japan | — | 3.1% |
| Gibraltar | — | 1.6% |
| Unresolved | — | 17.1% |
| Remaining 32 countries (1% or less each) | 13.1% combined | — |

Figure 2. Family submitter geography
Across industries, MSSPs, technology, and government appear prominently in both datasets. MSSP and technology figures may be influenced by higher security-team submission rates, while the exposure seen in education and government is more consistent with genuine targeting. Banking, manufacturing, and finance also feature prominently, aligning more closely with the campaign's invoice and VAT-themed lures.
| Industry | Risk score |
|---|---|
| MSSP | 41% |
| Education | 35% |
| Technologies | 24% |
| Government and administrations | 24% |
| Manufacturing | 21% |
| Banking | 20% |
| Telecommunications | 17% |
| Finance | 17% |
| Consulting | 14% |
| Health | 14% |
| Culture and entertainment | 13% |
| Civil society | 11% |
| Transport | 9% |
| Logistics | 7% |
| Agriculture and agribusiness | 6% |
| Energy | 6% |
| Hospitality | 3% |
| Defense | 1% |

Figure 3. Industry risk score, %
These figures represent where campaign samples were observed rather than confirmed compromises, so they should be treated as indicators of targeting focus and a proxy for the potential victim population.
For security leaders, the key takeaway is that defenses need to be product-agnostic. This campaign abuses legitimate, signed RMM software and can switch between vendors, so controls built around a specific tool or AV verdict will leave gaps. Ensure your SOC focuses on the delivery chain and unauthorized remote-access activity instead.
Treat the RMM install itself as a signal, whatever the product. GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise, and ITarian have all been abused in this campaign. Detection should focus on how the software reaches the environment, particularly installations originating from new free-hosting domains or compromised WordPress pages, rather than on the RMM product itself.
Build detection around persistent campaign patterns. Disposable Vercel infrastructure rotates rapidly: 94% of 240 observed hosts appeared for only a single day. Instead of relying primarily on domains, prioritize stable kit indicators, including the fmtt / font1.woff2, icons8-microsoft-word-94.png asset, and the secure.html → project/*.zip chain.
Account for password-protected archive delivery. The campaign pairs fake document pages with password-protected ZIP files and provides the password to the victim, helping payloads evade automated inspection. Mail-layer controls and user awareness should account for this delivery pattern.
Baseline authorized remote-access tooling. Maintain an inventory of approved RMM products and ensure the SOC can quickly identify unexpected installations or activity.
Give analysts behavioral and threat context in one investigation workflow. In this analysis, ANY.RUN's Interactive Sandbox exposed the delivery chain, browser activity, scripts, and network requests, while Threat Intelligence Lookup expanded persistent indicators into the wider campaign.
New *.vercel[.]app deployments appear more or less constantly, each only days old.
One of them, fillingconfirmation[.]vercel[.]app, had been registered just one day before it was observed. Vercel suits the operator well: every deployment comes with valid TLS, a trusted domain, and one-command redeployment. All this gives the lures the reputation needed to clear mail filters while remaining cheap enough to abandon at will.
The activity has continued since January 2026 at a steady monthly pace, with 18 to 57 new kit hosts appearing each month. Cloudflare, Kaseya/INKY, and CyberArmor have also reported on this activity, with findings consistent with what follows here.

Figure 4. The phishing email example
The attack begins with a phishing email linking to a disposable *.vercel[.]app page disguised as a legitimate document. The CRA/T4 lure is one example, alongside SSA, VAT, invoice, shipping, and other document-themed variants.
The page redirects to secure.html, which provides an access code and downloads a password-protected ZIP — the payload. Once the victim extracts and runs the VBS script inside, PowerShell downloads and installs a legitimate RMM agent, giving the operator hands-on-keyboard remote access.

Figure 5. The delivery chain
Using ANY.RUN's in-browser data inspection, we reconstructed the full browser-side chain, including DOM changes, redirects, page content, and screenshots of what the victim sees at each stage.
Every deployment ships essentially the same page, byte for byte. Several recurring DOM elements reveal the kit's distinctive handwriting:
An empty title.
A @font-face declaration for font-family:'fmtt' sourcing url(img/font1.woff2) — the shared font that links the broader family.
img src='img/icons8-microsoft-word-94.png' id='fd' alt='PDF Icon' — a Word icon persistently mislabeled as "PDF Icon."
A #rl red spinner element.
A three-hop meta-refresh chain: root page → secure.html → project/<lure>.zip.
The recurring "Downloading 2025 T4 Form…" and access-code text.

Figure 6. The Adobe phishing page. ANY.RUN Sandbox "Browser Data" view
For additional cover, the kit opens a harmless decoy PDF through legitimate OneDrive infrastructure (1drv[.]ms, onedrive[.]live[.]com, and canadaeast1-mediap[.]svc[.]ms). Its purpose is simply to make the download appear routine to the victim.
Using Static discovering in ANY.RUN's Interactive Sandbox, we inspected the VBS script responsible for launching the next stage of the attack.
The chain progresses only after the victim enters the on-page access code. This unlocks a single VBS script that uses FileSystemObject to launch POWERSHELL.EXE and download the next stage.
PowerShell does the rest: it skips the user profile, introduces a sleep delay to evade timing-based analysis, writes binary data to a stream, and downloads and installs the RMM MSI. Once installed, the RMM agent gives the operator live, hands-on-keyboard access to the system.

Figure 7. The fragment of VBS script. ANY.RUN Sandbox

Figure 8. The example of HTTP request to download password-protected archive
Evasion operates across multiple stages of the delivery chain. The first layer is the archive: project/<lure>.zip returns HTTP 200 but remains password-encrypted, leaving automated pipelines with an inert ZIP they cannot open. The VBS inside is extracted and executed only after the victim enters the on-page access code.
The second layer sits in front of payload delivery. The page fingerprints the browser, IP address, and geolocation using FingerprintJS, an hCaptcha challenge, and a "Green Spinner" gate. On some pages, the results are relayed to api.telegram[.]org, allowing the payload to be served only to visitors that pass the checks while filtering out suspected analysis environments.
The PowerShell stage adds timing-based evasion by calling sleep before reaching out for the MSI installer.
HTTP request analysis in ANY.RUN's Interactive Sandbox made these delivery and evasion flows visible. Following the network trail revealed a broader, highly distributed infrastructure.
Delivery infrastructure: The family includes 82 code-identical Vercel apps, each observed for only a single day, alongside GitHub Pages, Netlify, compromised legitimate websites, and throwaway domains. Vercel is particularly useful to the operator because each new deployment inherits valid TLS and domain reputation.
Payload staging: RMM installers are staged across rotating infrastructure, including Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, gofile[.]io, Dropbox, compromised sites, and raw-IP hosts.
RMM infrastructure: The remote-access product is interchangeable. At least five legitimate RMM products have appeared across the family, while the delivery chain remains largely unchanged.
The evidence behind each product is uneven, which bounds what any per-product signature can cover:
| RMM product | What backs it | Install / network artifacts measured |
|---|---|---|
| LogMeIn Rescue / Resolve | 46 cases in this arm; captured MSI LogMeInResolve_Unattended.msi |
Yes — LOGMEINRESCUE mutex on host |
| GoTo Resolve | Dominant product by network telemetry in this arm | Yes — TLS SNI and DNS to gotoresolve[.]com |
| ScreenConnect | 204 family cases, outside this arm | Identified by case tag |
| ConnectWise | 106 family cases, outside this arm | Identified by case tag |
| ITarian | 1 case | No |
Those measured artifacts cover the GoTo and LogMeIn slot only.
The RMM stage is the thinnest layer of evidence in the chain: 20 of the 137 arm cases are observed fetching the MSI, while the rest stop at the password-protected archive, and the same MSI appears in 150 cases index-wide, so it is staged across delivery arms beyond this kit.

Figure 9. Network Infrastructure
Neither the staging host nor the RMM backend identifies the operator. The MSI sits on shared, abused cloud storage, and the backend is each vendor's own infrastructure, so neither layer establishes that one operator is behind all of it. The delivery kit's handwriting is what ties the activity together.
The fact that the product in the RMM slot changes between arms is another reason why this slot is the weakest layer for building a durable signature.
The CRA/T4 arm is one part of a broader delivery framework whose document themes, domains, and RMM payloads change while the underlying kit remains stable. The shared fmtt web font (img/font1.woff2) provides a particularly strong pivot into that wider activity.

Figure 10. Cluster Expansion
| Arm | How to recognize it | Payload / behaviour |
|---|---|---|
| CRA/T4 Word on Vercel | icons8-microsoft-word-94.png (id=fd, alt='PDF Icon') + secure.html + project/*.zip on *.vercel[.]app; access-code ZIP |
Password-ZIP to VBS to PowerShell to GoTo Resolve / LogMeIn Rescue MSI |
| Adobe-PDF / SSA / compromised-WordPress siblings | Same fmtt / font1.woff2 font; paths /pdfviewer-updater/, /admin/ssaa/, /wp-content/file/ |
ScreenConnect / ConnectWise / other RMM tooling, plus Telegram victim-filtering |
To determine whether this is a shared phishing-as-a-service kit with several affiliates, we can use Threat Intelligence Lookup for cluster expansion.
With the following TI Lookup query, we can search through recent public sandbox analyses and identify this malicious activity.
TI Lookup:
url:"*img/font1.woff2" OR url:"*/icons8-microsoft-word-94.png" OR SHA256:"51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42"
The query returns 601 analysis cases across the three indicators. The font alone links 425 distinct kit URLs across 240 hosts and 155 IPs between February 5 and July 29, 2026, exposing activity well beyond the CRA/T4 arm.
The same fingerprint produced no matches across roughly 46,000 cases from ten unrelated malware families, supporting its use as an operation-specific marker rather than a generic web artifact.
The font1.woff2 query provides a direct measure of the family's delivery infrastructure. Across 174 days, it identified 425 distinct kit URLs on 240 hosts resolving to 155 IPs.
| Measure | Value |
|---|---|
| Distinct kit URLs | 425 |
| Unique hosts serving the kit | 240 |
| Unique resolving IPs | 155 |
| Observation window | 5 February to 29 July 2026 (174 days) |
| Hosts seen within a single day | 225 of 240 (94%) |
| Hosts seen over 3 days or less | 228 of 240 (95%) |
| Longest-lived host | docshared[.]org — 23 days |
| Busiest host | dashboarduat.paynnow[.]com — 45 kit URLs in 11.5 days |
The hosting breakdown shows how this infrastructure is distributed across different host types:
| Hosting type | Hosts | Kit URLs |
|---|---|---|
| Conventional websites (compromised or stood up) | 117 | 257 |
Vercel — *.vercel[.]app |
82 | 82 |
Throwaway registrations on cheap TLDs (.vu, .sbs, .cfd, .icu, .top, .one, .cyou, .shop, .online, .site) |
32 | 65 |
Dynamic DNS (ddnsking[.]com, swoop2[.]me, letsgo2[.]me, net2me[.]me) |
7 | 19 |
Netlify — *.netlify[.]app |
1 | 1 |
Backblaze B2 — f004.backblazeb2[.]com |
1 | 1 |
| Total | 240 | 425 |

Figure 11. Hosts by hosting type
Push-button deployment platforms account for 83 of the 240 hosts, with Vercel supplying 82 of them. Every Vercel app was observed on exactly one day with exactly one kit URL and was never reused, indicating a one-app-per-lure deployment model that makes domain-level blocking quickly obsolete.
| Lure theme in the Vercel subdomain | Apps |
|---|---|
CRA / T4 tax (2025t4ab1109061, crataxsummary1007341, officialsummarybycra) |
27 |
Generic shared document / file transfer (shared-doc820848110641, newfilesshared) |
25 |
Invoice / payment / VAT (invoice-49883-due, payment-recelpt) |
8 |
Adobe / PDF / Flash updater (adobe-upd, pdfviewer-nu, flash-updater) |
7 |
Streaming / invite / social (liveeventstream, kik2gethernow) |
7 |
US SSA / social security (socialsecuritystatementreceived0320) |
4 |
Shipping and logistics (ups-aw, upsawb4290324) |
4 |
| Total | 82 |
New hosts appear at a steady clip, while Vercel deployments arrive in bursts — 23 new apps in March, at the height of Canadian T4 season, and 20 more in July:
| Month (2026) | New hosts | of which Vercel apps | Kit URLs seen |
|---|---|---|---|
| February | 18 | 6 | 29 |
| March | 43 | 23 | 59 |
| April | 45 | 10 | 76 |
| May | 44 | 16 | 115 |
| June | 33 | 7 | 59 |
| July (to 29th) | 57 | 20 | 87 |
| Total | 240 | 82 | 425 |

Figure 12. New kit hosts first seen per month
The infrastructure also splits into two distinct URL patterns. All 83 Vercel and Netlify apps serve the kit directly from /img/font1.woff2, while 110 other hosts use per-recipient paths in the form /ftx/<slug>-<epoch>-<hex>/.
The embedded Unix timestamps reveal the campaign's operational tempo: the median link was first observed just 32 minutes after generation, and 77% within 24 hours. This strongly suggests that links are generated per recipient and used almost immediately.
Reputation follows the same divide. Of 425 URLs, 23 were already rated malicious when observed, all hosted on cheap-TLD throwaway domains. None were Vercel apps, suggesting that the platform provides the clean domain reputation the operator's own disposable domains lack.
This analysis uncovered a 46-country, US-first campaign that abuses legitimate RMM software while rapidly rotating domains, lures, and remote-access products. The more durable detection opportunity lies in the delivery framework: recurring kit patterns and unsolicited RMM installation rather than individual IOCs or product names.
Using ANY.RUN's Interactive Sandbox, we exposed the full attack chain, from browser activity and redirects to scripts, processes, and network traffic. Threat Intelligence Lookup then turned persistent indicators into pivots for uncovering related infrastructure and expanding the investigation across the wider campaign.
| Tactic | ATT&CK | Technique | Evidence |
|---|---|---|---|
| Resource Development | T1583.006 | Acquire Infrastructure: Web Services | The operator used 82 one-shot *.vercel[.]app deployments, one Netlify app, and *.github[.]io pages to host the lure kit. |
| Resource Development | T1583.001 | Acquire Infrastructure: Domains | The operator registered 32 throwaway domains on cheap TLDs and used 7 dynamic-DNS names to serve the same kit. |
| Resource Development | T1584 | Compromise Infrastructure | The operator used compromised legitimate websites — 8 confirmed in this arm, 117 conventional sites family-wide — to serve the icons8-microsoft-word-94.png kit path. |
| Initial Access | T1566.002 | Phishing: Spearphishing Link | The operator used a CRA/T4 spear-phishing email to link victims to a *.vercel[.]app lure page. |
| Execution | T1204.002 | User Execution: Malicious File | The operator used an on-page access code to induce the victim to extract and run the single VBS script. |
| Execution | T1059.005 / T1059.001 | Command and Scripting Interpreter: Visual Basic / PowerShell | The VBS script used FileSystemObject to launch PowerShell and download the next stage. |
| Defense Evasion | T1027 | Obfuscated/Encrypted Files: password-protected archive | The kit used a password-protected project/*.zip requiring the on-page access code to block automated extraction. |
| Defense Evasion | T1497 | Virtualization / Sandbox Evasion | The operator used Telegram-based victim filtering, browser/IP/geo fingerprinting, and sleep timing to evade analysis environments. |
| Command and Control | T1105 | Ingress Tool Transfer | The operator used PowerShell to download the RMM MSI from rotating S3 / R2 / GitHub / gofile / raw-IP staging. |
| Command and Control | T1219 | Remote Access Software | The operator used a signed RMM agent to establish hands-on-keyboard remote access — GoTo Resolve and LogMeIn Rescue in this arm, ScreenConnect and ConnectWise in sibling arms. |
| Command and Control | T1102 | Web Service | The kit used api.telegram[.]org to filter victims and conditionally deliver the payload. |
All indicators are defanged.
Kit handwriting (detection patterns)
*/secure.html on host *.vercel[.]app.*/project/*.zip on host *.vercel[.]app.*img/font1.woff2 — the family-wide font pivot (425 URLs / 240 hosts)./ftx/<6-char slug>-<10-digit epoch>-<12-hex>/ on non-platform hosts (289 URLs / 110 hosts); the epoch field dates the link's generation.font-family:'fmtt' + img/font1.woff2 + alt='PDF Icon' + "Access code is" text.Lure deployments (representative; 82 Vercel apps observed in total)
fillingconfirmation[.]vercel[.]appsharedconfirmationslip[.]vercel[.]appofficialsummarybycra[.]vercel[.]app2026t4form17718[.]vercel[.]appcrataxsummary1007341[.]vercel[.]appstatemendetailsfilessenderderf[.]netlify[.]appThrowaway domains carrying a malicious verdict at observation
quavix[.]vucevora[.]vuxorlira[.]vuvoretix[.]icuwurel[.]sbsmornixa[.]cfdgetdl[.]jorix[.]cyoupdfmarchlitestatementsscannedforyou[.]gixar[.]sbsreportstastementformarchreviewyourssaast[.]harnivo[.]cfdDynamic-DNS kit hosts (attacker-controlled subdomains of legitimate DDNS providers — block the host, not the provider)
54511[.]ddnsking[.]comdxy43[.]ddnsking[.]comdyb32[.]ddnsking[.]com67pon[.]swoop2[.]medcsi23[.]swoop2[.]messi11[.]letsgo2[.]meddn3[.]net2me[.]meCaptured RMM MSI
hxxps://commonerdays[.]vercel[.]app/LogMeInResolve_Unattended.msiPayload staging (attacker-controlled buckets)
mayteslaadvisorhq[.]s3[.]us-east-2[.]amazonaws[.]comopenfodervbs4view[.]ams3[.]cdn[.]digitaloceanspaces[.]comDurable origin IP
46.62.197[.]232:7000Compromised legitimate sites (kit path only)
hiltonheadislanddeals[.]comgonzalezjaramilloabogados[.]commybcdc[.]cataurusburgerco[.]com[.]auypatellawoffice[.]caelectrical-sei[.]comherculescalgarymovers[.]caquantechitsolutions[.]comKit page content hashes
41b731279b1778a9f578e4ed2589f46c4bef32793b292862cf96279a3ead1c41 (lure index page)132d864bb199105d639edb115249302243eafdb0fc21efb86cc6b6c0d49866f0 (secure.html gate page)51f0cc172ced2e90acbc01c2872c697644380e597076350a6b286c96ab7ccb42 (icons8-microsoft-word-94.png asset)