US Now Top Target in Global Phishing Campaign That Hijacks Remote Access Tools

A phishing operation first spotted using fake Canadian tax notices has spread to 46 countries, with nearly half of all sightings hitting American inboxes.

ThreatVectr Newsdesk· 3 min read
16:9 editorial photograph, full-frame edge-to-edge, of a hotel front-desk computer monitor glowing in a dimly lit reception area at night, the screen displaying
Share

Key points

  • Researchers at ANY.RUN have linked 601 separate cases to a single phishing operation now active in 46 countries.
  • The United States accounts for roughly 45% of observed activity, making it the campaign's top target.
  • The campaign was first flagged as Canadian in focus because early lures posed as Canada Revenue Agency tax forms.
  • Attackers trick victims into installing legitimate remote monitoring and management (RMM) software, which then hands the criminals full control of the computer.

A phishing campaign that researchers first pegged as a Canadian tax scam is far bigger than it looked. It now spans 46 countries, and the United States, not Canada, is taking the heaviest hits.

The finding comes from ANY.RUN, a malware analysis firm whose sandbox is widely used by incident responders. Its analysts connected 601 separate cases to the same operation. Around 45% of that activity traced back to victims in the US.

The campaign was originally tagged as Canada-focused because the early bait emails carried fake Canada Revenue Agency tax forms. That framing was misleading. The tax lure was one costume among many.

What are the criminals actually doing?

They are tricking people into installing remote access software on their own computers. Once the program is running, the attacker on the other end can see the screen, move the mouse, open files, and drop further malware, all without setting off the usual alarms.

The software involved is not itself malicious. Tools like ConnectWise ScreenConnect, AnyDesk, Atera and Splashtop are sold to IT departments to fix laptops from a distance. They are collectively called RMM, short for remote monitoring and management. Because these programs are signed by legitimate vendors, antivirus products often wave them through.

That is the trick. The criminals do not need to write clever malware. They just need one employee to click an installer.

How does the lure work?

A victim receives an email that looks like a routine business document: a tax notice, an invoice, a shipping update, a purchase order. The link leads to a PDF or a webpage that offers a small installer. Running it silently sets up the remote access tool and phones home to the attacker.

From there, the operator can steal saved passwords, read email, move to other machines on the network, or hand access off to a ransomware crew.

As The Hacker News noted in earlier coverage, this pattern of abusing legitimate remote support software has become one of the fastest growing intrusion methods of the past two years. It sidesteps a lot of the defences companies have spent money on.

Where is the campaign hitting hardest?

Region Share of observed activity
United States ~45%
Canada Significant, original focus
Other countries 44 more, remainder of cases
Total cases linked 601

The US share dwarfs any single other country. Canada remains heavily targeted, which is why the operation was misread as regional at first. The other 44 countries pick up the rest.

Should ordinary workers be worried?

Yes, but the defence is simple. If an email asks you to download a small program to view a tax form, an invoice, or a delivery notice, stop. Real tax agencies and real suppliers do not work that way.

Ask your IT team before installing anything, even if the software has a familiar name like AnyDesk or ScreenConnect. Those names are exactly what the criminals are counting on.

If you have already run something like that, tell your employer today. Speed matters. The longer the remote session stays open, the more the operator can take.

© 2026 Threat Vectr