RMM phishing campaign spreads across 46 countries
A phishing operation that began with fake Canadian tax documents has grown into a campaign hitting targets in 46 countries, with the United States now the top target at about 45 percent of observed activity. The attackers send fake shipping, invoice, tax, and Social Security documents to trick people into installing legitimate remote monitoring and management software, which then gives the attacker remote control of the computer. Researchers at ANY.RUN have linked over 600 cases to the operation, which changes its hosting daily to dodge detection.
- Started
- Aug 10, 2026
- Latest activity
- Sep 6, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States, Canada
- Sectors
- Education, Technology, Government, Finance, Manufacturing
- Scale
- about 601 tracked phishing cases across 46 countries
Current status
No credible update after 2026-09-06 was found; the latest known evidence said the campaign remained active.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Impact
Victims who fall for the lure install real remote monitoring and management software, giving an outside attacker hands-on control of their computer. No specific data theft or financial loss has been publicly confirmed for named victims yet.
What to do
Do not open unexpected shipping, invoice, tax, or Social Security documents or install any remote-access or IT support software an email asks you to install, even if it looks legitimate.
Timeline
-
Sep 6, 2026
ANY.RUN said the campaign remains active, with attackers switching between remote-access products and rotating hosting daily. No new victim count, named victims, or attribution were reported.
Activelinkedin.com -
Sep 3, 2026
The Hacker News and SC World reported 601 linked cases and daily rotating infrastructure, confirming the campaign is still active.
Activethehackernews.com -
Aug 14, 2026
ANY.RUN research showed the operation spans 46 countries with about 45 percent of activity in the United States.
Activecybersecuritynews.com -
Aug 10, 2026
Researchers reported a phishing campaign using fake Canada Revenue Agency tax documents to push victims into installing legitimate RMM software.
Emergingcybersecuritynews.com
Sources
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries The Hacker News Sep 3, 2026
- RMM remote-access tools phished in 46 countries SC World Sep 3, 2026
- Microsoft 365 phishing steals work accounts Cyber Security News Aug 14, 2026
- Microsoft Office HTML Injection bug can expose secrets Cyber Security News Aug 10, 2026
- ANY.RUN | LinkedIn LinkedIn Sep 6, 2026
- AI Attack Surfaces and Supply Chain Threats Define the Week eSecurity Planet Sep 4, 2026
Related reports
- Phishing campaign tricks victims into installing remote-access tools Sep 3, 2026
- RMM remote-access tools phished in 46 countries Sep 3, 2026
- Microsoft 365 phishing steals work accounts Aug 14, 2026
- Microsoft Office HTML Injection bug can expose secrets Aug 10, 2026