# The Canada Tax Lure Was a Red Herring. The Real Target Was America.
Researchers tracking what looked like a Canada-focused phishing operation built around Canada Revenue Agency tax forms got a surprise when they pulled the thread: the campaign runs across 46 countries, and the United States — not Canada — accounts for roughly 45% of all observed activity. The CRA branding wasn't a signal of who the attackers were after. It was a distraction.
ANY.RUN's sandbox telemetry tied 601 confirmed cases to the broader operation. That number almost certainly undercounts the real footprint. Sandboxes catch what analysts submit. Most enterprise infections never get detonated in a research environment.
What these attackers are delivering makes this worth paying attention to: Remote Monitoring and Management (RMM) tools. Not ransomware. Not a stealer. Legitimate software your IT department probably already trusts.
## Why RMM Is the Payload Now
The shift toward RMM-as-payload is one of the more significant changes in the threat landscape over the last two years, and it still doesn't get enough coverage outside the incident response community.
Here's why attackers love it. RMM tools — ConnectWise, AnyDesk, Splashtop, and their relatives — are designed to give remote users persistent, authenticated access to a machine. They communicate over encrypted channels. They're whitelisted in most endpoint security products because your IT vendor uses them legitimately. When an attacker installs one through a phishing lure, they gain the same kind of access a help desk technician would have: persistent, trusted, low-friction, and nearly invisible to signature-based detection.
CISA called this out explicitly in a 2023 advisory, after analysts documented the Silent Ransom Group (also known as Luna Moth) running extended RMM-based extortion campaigns. Those attackers would gain RMM access, spend weeks enumerating the environment, and then exfiltrate data before ever deploying anything that looked like traditional malware. By the time the victim noticed, the sensitive data was already gone.
The campaign ANY.RUN documented appears to follow a similar playbook. The tax-form lure is credible social engineering — people expect documents around filing season, and a lure that mimics a government agency creates urgency without triggering obvious suspicion. Once a victim executes the payload, the attacker has a quiet foothold.
## 46 Countries, One Operational Core
The geographic breadth here is notable. Operations that span 46 countries in a coordinated way typically indicate either a well-resourced threat actor with a defined target list, or a franchise-style criminal model where a central toolkit gets distributed to regional operators who customize the lure for their jurisdiction.
The CRA lure initially made analysts assume Canadian origin or Canadian targeting. That kind of geographic misdirection is occasionally deliberate — attackers seed specific-looking infrastructure to muddy attribution — but it may also just reflect where the campaign's initial test cases were run. Either way, the US emerged as the dominant target by a wide margin.
That tracks. US targets tend to have higher payouts in extortion scenarios, more valuable credentials, and deeper integration with the kind of enterprise tools RMM access can exploit. A compromised US corporate machine often opens doors to cloud environments, financial accounts, and inter-company trust relationships that translate into real money.
## What the 601 Cases Don't Show You
The ANY.RUN figure is instructive but limited. The research connects 601 sandbox-analyzed cases to the operation — but sandbox telemetry reflects what security teams submitted for analysis, which skews toward organizations with mature detection capabilities. Organizations that actually got compromised and didn't know it aren't in the count.
This is a consistent blind spot in phishing campaign reporting. We see the cases that got caught. The denominator — how many worked — is unknown. For RMM-based campaigns specifically, the gap between observed and actual can be significant, because there's no obvious malware signature to trigger an alert.
---
## HackWire Analysis
The operational detail that most coverage will miss: this campaign's apparent success at appearing geographically limited before researchers expanded scope should be a red flag about how attribution and triage decisions get made in enterprise environments.
When a phishing campaign presents with a Canada Revenue Agency lure, a US-based SOC analyst is likely to deprioritize it — it's not their tax authority, the lure doesn't fit their users, and it reads as someone else's problem. That's exactly the kind of cognitive shortcut sophisticated attackers exploit. The lure doesn't need to be convincing to every potential victim. It needs to generate enough noise in adjacent markets to deflect attention while the real targeting proceeds.
The deeper issue is that RMM-phishing campaigns have now outlasted the early-warning period. CISA flagged RMM abuse in 2023. Threat intel vendors wrote it up. And yet the vector keeps working — because the fundamental problem (legitimate software that bypasses endpoint detection) hasn't been solved. Organizations that haven't explicitly audited which RMM tools are authorized in their environment, who installed them, and whether any instances are phoning home to unknown infrastructure are flying blind.
Concrete defensive actions:
The 601 cases any.RUN documented are the visible part. The rest is still in someone's environment, waiting.
— HackWire Editorial
---
## Related Coverage