Blog Main Image
September 8, 2026

The Phishing Attack That Installs Real Software

An accounts assistant opens an email about an overdue invoice. The link takes her to a page with a valid certificate and a familiar document icon, and the page politely supplies an access code to open the attached file. She types the code, runs the file, and a PDF opens on screen. No warning appears and nothing is blocked, because nothing that reached her laptop was malware. What installed itself quietly in the background was a genuine, commercially signed remote support tool, and somebody outside the organisation now has hands on the keyboard.

Threat intelligence company ANY.RUN published analysis in late August 2026 of a phishing operation built on exactly that idea. What first looked like a Canadian tax scam turned out to be one arm of a campaign spanning 46 countries, with around 45 percent of observed activity associated with the United States. The lures change constantly. The machinery underneath barely changes at all.

A campaign assembled entirely from legitimate parts

The operation was first noticed through fake Canada Revenue Agency T4 tax forms, a lure the agency covers in its own guide to recognising a scam. Pivoting on shared assets in the phishing kit, the researchers connected 601 analysis cases to a much wider family of activity, with North America accounting for 61 percent of cases and the remainder spread across 46 countries. Education, technology and government appear prominently in the data, alongside banking, finance and manufacturing, which fits the invoice and VAT themed lures.

The final payload is not a virus. It is a remote monitoring and management (RMM) agent, the same category of software an IT team or managed service provider uses to support staff laptops. At least five legitimate products have appeared across the campaign, including GoTo Resolve, LogMeIn Rescue, ScreenConnect, ConnectWise and ITarian. None of those vendors has done anything wrong here. Their software is being installed by the person sitting at the keyboard, under false pretences, and then used for something it was never sold for.

One caveat matters. These figures record where campaign samples were observed and submitted for analysis, not confirmed compromises. They show where the operation is aiming, not how many organisations it reached.

Why real software makes such an effective payload

Security agencies flagged this pattern years ago. In a joint advisory, CISA, the NSA and MS-ISAC warned network defenders about the malicious use of legitimate RMM software after identifying a widespread campaign that used phishing emails to get victims to download commercial remote access tools. Their assessment set out the advantages plainly: RMM software generally does not trigger antivirus or antimalware defences, portable versions can run without administrator rights and so slip past software management policies, and using it lets an attacker avoid writing custom malware entirely.

That last point matters more than it sounds. A great deal of security spending assumes there is a malicious file somewhere in the chain to find. Here the file is a signed installer from a real company, doing exactly what it says on the tin. Every layer is legitimate. Only the intent is not.

The lure changes, the kit stays the same

The delivery side is deliberately disposable. ANY.RUN tracked 425 phishing kit URLs across 240 hosts, and 94 percent of those hosts were seen on only a single day. Much of the hosting sat on free deployment platforms, where every new app inherits a valid certificate and a trusted domain name at no cost. Links appear to be generated for individual recipients and used almost immediately: the median link was first observed just 32 minutes after it was created, and 77 percent within a day.

Blocking domains, then, is a treadmill. Cloudflare's Cloudforce One team documented the same style of attack between November 2025 and January 2026, with lures built around unpaid invoices, shipping documents and a legal threat, all funnelling towards the same signed remote access tool. The document theme is interchangeable. So is the RMM product. The kit is the constant.

The access code does two jobs at once

The most instructive detail is the small one. The phishing page hands the visitor a password and a password protected archive. Technically, that defeats automated inspection: a scanner can download the file, confirm it is a valid archive, and get no further, because the contents are encrypted and the key lives on a web page it never visited.

Psychologically, it does something else. Being given an access code feels like security, not like an obstacle. It resembles the two step process people already associate with confidential documents from a bank or a solicitor, and typing it in turns the recipient from a reader into a participant. The pages add browser and location checks on top, so suspected analysis environments are served nothing at all, and in some cases a harmless decoy PDF opens through genuine cloud storage to make the whole thing feel routine.

Swimlane diagram showing the same RMM phishing attack from three perspectives: what the attacker sets up, what the person experiences, and what security tooling has to work with
The same four stages seen three ways. The middle lane is where the attack can still be stopped.

What this asks of the people in your organisation

It would be unreasonable to expect an accounts assistant to recognise a signed installer or know which remote support products her IT team has standardised on. That is not a fair test.

There is a fairer test, and the campaign hands it to us. At some point in every version of this attack, a document the recipient was expecting to read turns into software the recipient has to install. That transition is visible, unusual, and something a person can be equipped to notice. Nobody needs to identify the product. They only need to know that reading an invoice should never require installing a support tool, and who to tell when it does.

That is where a reporting culture earns its keep. In this campaign the gap between the email arriving and the attacker having remote control can be minutes. A report that arrives while the attacker is still setting up is worth far more than a perfect detection rule written a week later.

Practical steps for defenders

  • Write down which remote support products your organisation actually uses, and tell staff the list. People cannot flag an unexpected tool if they have never been told what the expected one looks like.
  • Use application control to prevent installation and execution of unapproved remote access software, including portable versions that run without administrator rights.
  • Treat any unexpected RMM installation as a signal in its own right, whatever the product name. Detection built around one vendor will miss the next arm of the campaign.
  • Handle password protected archives at the mail layer, particularly where the password is supplied alongside them. That combination has very few honest uses.
  • Give people one clear rule ("a document should never ask you to install software") and a reporting route that takes one click, with no fear of being blamed for a false alarm.
  • Rehearse this specific shape in simulations, including the access code step, so the pattern is familiar before it arrives for real. The NCSC's phishing guidance sets out how these layers fit together without piling the burden onto individuals.

The bottom line

Attackers do not need to break anything technical when they can borrow something legitimate. Signed software, valid certificates, reputable hosting and encrypted archives are all doing their jobs correctly here, and the attack works because of that rather than in spite of it. As reporting on the research put it, individual domains and products are disposable while the delivery chain endures.

Which leaves one durable control in the middle of the chain. A person who has been shown this pattern, given a simple rule and a fast way to raise a hand is not the weakest link in that diagram. On a good day they are the only layer that was ever going to see it coming.

Phishing Tackle offers the tools businesses need to strengthen their human risk strategies, with multi-platform testing, real-time behavioural insights, and actionable data to keep your organisation ahead of modern cyber threats.

Contact us today to learn how Phishing Tackle can help safeguard your organisation from the growing array of cyber risks.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Scroll To Top Arrow