← Blog
For businesses

That "Tax Form" Wants You to Install Something. That's the Whole Attack.

Explore an AI summary

Most scams try to steal something from you directly: a password, a card number, a login code. This one is quieter. It gets you to install a piece of ordinary, legitimate software, and then a stranger uses that software to run your computer from somewhere else.

Researchers at ANY.RUN traced a phishing operation that spans 46 countries and connected 601 cases to a single campaign, with about 45% of the activity aimed at the United States, making it the top target. The lure is always a document you were plausibly expecting: a tax notice, an invoice, a shipping update, an Adobe PDF. The goal is not to steal a password on the spot. It is to get you to download and install remote monitoring and management (RMM) software, the same kind of tool an IT department uses to manage computers, so the attacker can quietly take over.

It is worth understanding, because the trick works on careful people. There is no obvious malware, no dramatic warning, and often nothing your antivirus objects to.


Key takeaways

  • A phishing campaign across 46 countries uses fake documents (tax forms, invoices, shipping and UPS notices, Adobe PDFs, US Social Security themes) to trick people into installing legitimate remote-access software an attacker controls (source).

  • The US is the top target, tied to about 45% of observed activity, with education, technology, and government among the most-hit sectors, alongside banking, finance, and manufacturing.

  • The software installed is real, commercial IT software, not a traditional virus, which is exactly why antivirus and reputation checks often let it through.

  • The pages that deliver it are hosted on disposable infrastructure that changes daily: researchers found 425 kit URLs across 240 hosts, 94% of them live for only a single day (source).

  • The reliable place for an individual to stop this is before the download: recognizing the fake document page for what it is, and pausing the file it wants you to run.


Keep your business safe from online threats

Haven for Business protects every employee from phishing, fake sites, and browser-based attacks.

How the fake document trick works

The attack has a simple shape, and every step is designed to feel routine.

First, you get a message about a document. It might be a tax form from a revenue agency, an unpaid invoice, a shipping notice from a courier, or an Adobe PDF you need to "review." The campaign rotates these lures to match whoever it is targeting, which is why the same operation shows up as a tax scam in one country and a shipping scam in another.

The link takes you to a page that looks like a normal document viewer or download page. Behind the scenes, that page is hosted on throwaway infrastructure. Researchers saw the campaign use services like Vercel, GitHub Pages, and Netlify, with the actual files staged on well-known storage services such as Amazon S3, Dropbox, and others. Using trusted, familiar services is part of the disguise: nothing about the web address screams "danger."

Then the page asks you to open the document, which means downloading a file, often inside a password-protected archive (the password is helpfully provided, which also lets the file slip past some email filters). When you run it, it does not install a tax form or an invoice. It installs a real remote monitoring and management tool, the category of software IT teams legitimately use to manage machines remotely.

From that point on, the attacker is connected to your computer through commercial software that is working exactly as designed. They can see your files, watch what you do, install more programs, and use your machine as a foothold. Nothing had to be "hacked." You installed the access yourself, believing you were opening a document.


Why your antivirus may wave it through

The clever part of this campaign is that the payload is not malware in the traditional sense. Remote monitoring and management software is legitimate, signed, commercial software. Millions of businesses run it on purpose. So a security tool that decides what to block based on "is this a known bad file" has a genuine problem here: the file is not bad. It is a real product being used for a bad reason.

The researchers make this point directly: detection cannot depend only on malware verdicts, reputation scores, or individual indicators, because the individual pieces keep changing and, in the case of the software itself, are not malicious at all. The infrastructure rotates daily. The RMM product can be swapped for a different vendor's tool at any time. What stays constant is the shape of the trick: a fake document, a page that hosts a download, and a file that quietly hands over remote control.

This is the same pattern we have written about before in other clothing. In the fake CNN "app" scam, a lookalike news site pushed a legitimate remote-administration tool as a "free app." In the fake COLDCARD "hardware audit" email, a phishing message told crypto owners to install an "audit tool" that was actually ConnectWise ScreenConnect, a real remote-access program the attacker controlled. Different bait, identical move: get a real remote-control tool onto your machine under a believable pretext.


Why this is hard to spot in the moment

The reason careful people fall for this is that every individual signal looks fine. The document is one you might genuinely receive. The page is on a service you have heard of. The download is a signed, real product. As we argued in why modern phishing no longer looks like phishing, the old tells, typos, ugly design, obviously fake addresses, have been engineered out. You are left trying to judge intent from a page that has been built specifically to look legitimate.

Asking yourself "does this look real?" is no longer a reliable test, because the answer is designed to be yes. The better question is "is this page actually who it claims to be, and should I be running this file at all?" That is a harder question to answer by eye, and it is exactly the question that has to be answered before you click download.


Where this can actually be stopped

If the file itself is a real product your antivirus has no reason to block, and the page is built to look legitimate, the defense has to move earlier, to the moment before the download, in the browser where you are standing.

That is where Haven works. Haven is a browser extension that checks whether a page truly is who it claims to be, rather than trusting how convincing it looks. When you land on a page impersonating a courier, a tax agency, or a document service to push a download, Haven flags it as a fake or impersonated page before you act on it. And because the whole attack turns on getting you to run a file, Haven pauses risky downloads so you can stop and check before something lands on your machine, instead of after. You can read more about how that works on our download protection page.

To be precise about what this does and does not do: Haven works at the delivery step, the fake page and the download, which is the point where an individual can actually intervene. It is a browser extension, not an endpoint security product. Once remote monitoring software is already installed and running on a computer, detecting and removing that activity is the job of endpoint protection and, for organizations, a security team, not a browser extension. Haven's role is to keep you from reaching that step: to catch the impersonated page and the unexpected download before the remote-access tool ever gets installed.

If you think you already installed something like this, treat the computer as compromised: disconnect it from the internet, change important passwords from a different device, and get help from a trusted professional or your IT team.

For small teams, where a single person opening a fake invoice can expose the whole business, Haven for Business extends this browser-level check across everyone's browser. That matters here specifically because the campaign leans on documents that land in work inboxes, invoices, tax notices, shipping updates, and small businesses often have no security team standing between an employee and a convincing fake.

The lesson underneath this campaign is the one running through every modern attack: you can no longer trust that something is safe just because it looks routine and comes wrapped in familiar logos. The document you were expecting is exactly what a good attacker will pretend to send. The safest habit is to confirm what a page really is, and think twice about what it wants you to run, before you hand over the keys.


About Haven

Haven is a browser extension that helps people make safer trust decisions online, before a scam can cost anything. It works at the moment someone is about to click a link or enter a password, flagging fake and impersonated login pages, suspicious links, and look-alike sites, and pausing risky downloads. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of the user, so it can catch brand-new and convincing fakes that other tools miss.

Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.

Frequently asked questions

What is RMM phishing?
RMM phishing is a scam that tricks you into installing remote monitoring and management software, the legitimate kind of tool IT teams use to manage computers remotely, so an attacker can control your machine. Instead of stealing a password directly, the attacker sends a fake document (a tax form, invoice, or shipping notice) that leads to a page pushing a download. When you run it, you install real remote-access software the attacker then uses to view your files, run programs, and operate your computer from afar. Researchers at ANY.RUN documented a campaign using this method across 46 countries, with the United States as the top target.
Why didn't my antivirus stop the download?
Because the software being installed is not a traditional virus. Remote monitoring and management tools are legitimate, signed, commercial products used by millions of businesses on purpose. A security tool that blocks files based on whether they are known to be malicious has little reason to stop a real product. That is why this kind of attack often slips past antivirus and reputation checks, and why the most reliable defense is to avoid the fake page and the unexpected download in the first place.
What documents do these fake-document scams pretend to be?
The campaign rotates its lures to match the target. Documented examples include tax notices (such as revenue-agency forms), unpaid invoices, shipping and courier notices like UPS updates, Adobe PDFs to "review," and US Social Security Administration themes. The file is often delivered inside a password-protected archive, with the password provided in the message, which helps it slip past some email filters. The specific document changes, but the goal is always the same: get you to open a file that installs remote-access software.
How can I tell if a document download is a scam?
Be cautious whenever a message about a document sends you to a page that wants you to download and run a file, especially inside a password-protected archive. Signs to watch for: you were not expecting the document, the sender pressures you to open it, or the download is an installer or executable rather than a plain PDF you can simply view. When in doubt, do not open the file. Go directly to the real organization's official website or app, or contact them through a known channel, rather than following the link or running the attachment.
What should I do if I already installed the software?
Treat the computer as compromised. Disconnect it from the internet to cut off the remote connection, change important passwords from a different, clean device, and get help from a trusted professional or, at work, your IT or security team. If it is a work computer, report it immediately so the team can revoke access and check for further activity. Removing installed remote-access software and confirming the machine is clean is a job for endpoint security tools and IT support, not a browser extension.
How does Haven help against RMM and fake-document phishing?
Haven is a browser extension that checks whether a page truly is who it claims to be, rather than trusting how convincing it looks. When you land on a page impersonating a courier, tax agency, or document service to push a download, Haven flags it as a fake or impersonated page, and because the attack depends on getting you to run a file, Haven pauses risky downloads so you can stop and check before something lands. Haven works at the delivery step, the fake page and the download, which is where an individual can actually intervene. It is not an endpoint security product and cannot detect or remove remote-access software already installed and running; that requires endpoint protection and, for organizations, a security team. Haven for Business extends this browser-level check across a whole team.