A phishing campaign using legitimate RMM tools has hit 46 countries, with the U.S. as the top target at 45% of cases. Here's how to spot the threat.
You'd think that after years of warnings, we'd all be pretty good at spotting a phishing email by now. But the bad guys keep raising the bar. The latest trick? Using legitimate remote monitoring and management (RMM) tools to slip past your defenses.
Security researchers at ANY.RUN recently uncovered a massive phishing operation that initially looked like a Canada-only problem. The lure was a fake Canada Revenue Agency (CRA) tax form. But dig a little deeper, and the truth is far more concerning: this campaign has hit 46 countries, and the United States is the primary target.
### What Exactly Is an RMM Phishing Attack?
RMM tools are software that IT teams use to manage computers remotely. Think of them as a digital master key for your entire network. Cybercriminals love these tools because they're trusted, they have deep system access, and they don't trigger the same alarms as traditional malware.
In this campaign, attackers craft emails that look like official tax documents. The email contains a link or attachment that, when clicked, initiates a connection through a legitimate RMM platform. Once connected, the attacker essentially has remote control of the machine. They can steal files, capture keystrokes, or deploy ransomware.
> The scariest part? You might not even realize you've been compromised until it's far too late. The tool looks legitimate, and the session looks like routine maintenance.
### The Numbers Behind the Threat
ANY.RUN's research team flagged 601 separate cases linked to this broader operation. Of those, a staggering 45% were tied to U.S. users. That makes America the campaign's number one hunting ground by a huge margin.
To put that in perspective, no other single country came close. The campaign isn't just broad; it's targeted. The attackers are going where the money is, and that means U.S. businesses and taxpayers are squarely in the crosshairs.
### Why the United States?
There are a few reasons why the U.S. gets hit so hard. For starters, we have a massive number of internet-connected businesses. More endpoints mean more opportunities. But there's also the tax factor. The original Canadian lure worked well, so the attackers adapted it for the U.S. market. Fake IRS forms are just as convincing, if not more so.
Another angle is the sheer value of U.S. corporate data. If an attacker gets into one American accounting firm, they might access financial records for hundreds of clients. That's a goldmine. RMM tools give them a quiet way in without setting off the usual alarm bells.
### How to Protect Yourself
So, what can you do? First, never click on unsolicited tax forms or financial documents sent via email. If you get a message from the IRS or a tax service, go directly to the official website instead of using the link in the email.
Second, watch for RMM software you didn't install. If you see a new remote access tool pop up on your system, that's a massive red flag. Most legitimate IT teams use a small set of known tools. Anything unfamiliar should be investigated immediately.
Third, enable multi-factor authentication everywhere you can. Even if an attacker gets your password, MFA can stop them from completing the connection. It's not a perfect shield, but it adds a critical layer of friction.
### The Bottom Line for U.S. Professionals
For anyone working in cybersecurity or IT management, this campaign is a wake-up call. The threats are no longer just about sketchy links from unknown senders. Criminals are weaponizing trusted business tools against us.
Stay alert, keep your software updated, and educate your team about these specific tactics. The attackers are counting on you being too busy to notice. Don't give them that advantage.
This isn't about fear-mongering. It's about awareness. Knowing how these campaigns operate gives you the power to stop them before they start. And in a world where the U.S. is the top target, that awareness has never been more critical.