Security1 distinct publisher3 min readPublished
The CRA tax forms were one regional skin on an operation that lands hardest in the US. With 94% of its kit URLs alive for a single day, the durable indicators are the kit's own files rather than the hosts serving them.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The stable part of this operation is the delivery chain. A lure document points at a page that hands over a password-protected archive, and ANY.RUN says the same structure recurs across otherwise unrelated hosts: secure.html leading to project/*.zip, the same font1.woff2, the same icons8-microsoft-word-94.png [7][8]. That reuse is what stitched 601 separate cases into one campaign [2]. The archive password serves an operational purpose rather than a courtesy to the victim: it keeps mail-layer scanners from reading the contents, which is why the vendor's own guidance puts archive handling at the gateway rather than on the endpoint [9].
The rotation numbers make the blocklist problem plain. Of 425 kit URLs, 94% were seen on a single day, so roughly 400 were spent and gone, leaving about 25 with any life beyond their first [5][14]. Those 425 URLs sat on 240 hosts, about 1.8 URLs per host, meaning hosts are close to single-use too [16]. Apply the 45% US share to the 601 cases and you get on the order of 270 US cases in the set [3][15]. An indicator feed keyed to domains is describing infrastructure that was already retired before the feed shipped.
What lands on the host is licensed remote monitoring and management software [2]. No malicious binary exists to convict, which is ANY.RUN's stated reason that malware verdicts, reputation scoring and single IOCs all under-detect this chain [12]. The detection point is the install: an RMM agent appearing on a machine where no ticket authorized it. That requires knowing which agents are sanctioned, on which hosts, under which support contract, and treating everything else as an intrusion regardless of vendor [10]. Lure themes shift to fit the target, with UPS shipping notices, Adobe PDF prompts, tax notices, US Social Security Administration themes and invoices all in the observed set [4]. The Canada Revenue Agency documents that first framed this as Canadian targeting were localization, applied to 46 countries' worth of letterhead [1].
The sourcing here deserves a closer look. Both URLs supplied here are the same article from the same publisher, drawing on one vendor's telemetry, and the piece doubles as promotion for that vendor's sandbox and lookup products [18][13]. No threat actor is named and no dates are given for the activity window [17]. The 45% figure is described as observed activity, which in a sandbox dataset counts submissions rather than confirmed victims, so the US share partly measures who uploads samples. The parts that survive that caveat are the structural ones: 425 URLs, 240 hosts, single-day lifetimes, and a kit fingerprint that has not moved [5][7]. Education, technology and government sit at the top of the targeted sectors, with banking, finance and manufacturing also present [11].
Ranked by verification strength, evidence, and original report placement.
An RMM phishing campaign initially associated with Canadian targeting, because it used Canada Revenue Agency (CRA) tax forms as lures, turned out to be part of a broader campaign spanning 46 countries.
ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) software.
Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target.
Attackers adapt lures to different targets, using shipping and UPS communications, Adobe PDFs, tax notices, US Social Security Administration themes, invoices and other documents.
ANY.RUN researchers identified 425 kit URLs across 240 hosts, 94% of which were observed for only a single day.
Delivery has used Vercel, GitHub Pages, Netlify, compromised websites and other infrastructure; payloads have been staged through Amazon S3, Cloudflare R2, GitHub, DigitalOcean Spaces, Dropbox and GoFile.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
TA4922 parks Donut Loader in the same folder as a signed executable1 distinct publisher
security
Mirage2FA: 4,532 domains later, "we have MFA" is not an answer to the auditor1 distinct publisher
build
A spec-clean 402 is not a listing: x402scan bounced the tunnel, not the JSON1 distinct publisher
build
With CRA out of React's docs, the new project default is a rendering decision1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, one outlet, printed twice
601 cases, 46 countries, 45% US, 425 URLs on 240 hosts — every figure originates with ANY.RUN and reaches readers through a single Hacker News post published twice. The kit artefacts are named specifically enough that a team could hunt for them, which is more than most vendor summaries offer, but there is no indicator list, no hashes, no collection window and no description of how cases were linked.
Broad footprint, single telemetry lens
The reach is the substance: 601 linked cases in 46 countries, sectors from education to manufacturing, and 425 short-lived kit URLs. But these are counts of what one vendor's sandbox submissions and lookups happened to see, not counts of compromised organisations — a footprint whose national ranking follows ANY.RUN's customer geography at least as much as the attacker's aim.
Headline ranks a sandbox, not a world
'US becomes top target' turns one vendor's submission mix into a global league table, and 45% of unstated totals is doing heavy work for that claim. Meanwhile the finding with real shelf life — that a rotating host is disposable but a reused font file and a secure.html to project/*.zip path are not — sits below the geography and is undersold. The overstatement is in the framing, not the numbers.
Research and sales pitch, same page
The piece carries a 'Power your SOC with ANY.RUN' line, cites intelligence from 16,000-plus organizations as proof of reach, and credits its two products by name for the findings. The advice that follows — stop trusting domains and verdicts, buy behavioural context — describes what the vendor sells. That does not make the artefacts wrong; it does mean the framing was chosen by an interested party and nobody else weighed in.
Clear on what was said, thin on whether it holds
The text is unambiguous and internally consistent, so we can characterise what was claimed precisely and check the arithmetic behind it cleanly. Verification is another matter: one research team, one outlet, a duplicate posting, no dates, no actor. What we are confident about is the reporting, not the campaign.