Most scams try to steal something from you directly: a password, a card number, a login code. This one is quieter. It gets you to install a piece of ordinary, legitimate software, and then a stranger uses that software to run your computer from somewhere else.
Researchers at ANY.RUN traced a phishing operation that spans 46 countries and connected 601 cases to a single campaign, with about 45% of the activity aimed at the United States, making it the top target. The lure is always a document you were plausibly expecting: a tax notice, an invoice, a shipping update, an Adobe PDF. The goal is not to steal a password on the spot. It is to get you to download and install remote monitoring and management (RMM) software, the same kind of tool an IT department uses to manage computers, so the attacker can quietly take over.
It is worth understanding, because the trick works on careful people. There is no obvious malware, no dramatic warning, and often nothing your antivirus objects to.
Key takeaways
A phishing campaign across 46 countries uses fake documents (tax forms, invoices, shipping and UPS notices, Adobe PDFs, US Social Security themes) to trick people into installing legitimate remote-access software an attacker controls (source).
The US is the top target, tied to about 45% of observed activity, with education, technology, and government among the most-hit sectors, alongside banking, finance, and manufacturing.
The software installed is real, commercial IT software, not a traditional virus, which is exactly why antivirus and reputation checks often let it through.
The pages that deliver it are hosted on disposable infrastructure that changes daily: researchers found 425 kit URLs across 240 hosts, 94% of them live for only a single day (source).
The reliable place for an individual to stop this is before the download: recognizing the fake document page for what it is, and pausing the file it wants you to run.
How the fake document trick works
The attack has a simple shape, and every step is designed to feel routine.
First, you get a message about a document. It might be a tax form from a revenue agency, an unpaid invoice, a shipping notice from a courier, or an Adobe PDF you need to "review." The campaign rotates these lures to match whoever it is targeting, which is why the same operation shows up as a tax scam in one country and a shipping scam in another.
The link takes you to a page that looks like a normal document viewer or download page. Behind the scenes, that page is hosted on throwaway infrastructure. Researchers saw the campaign use services like Vercel, GitHub Pages, and Netlify, with the actual files staged on well-known storage services such as Amazon S3, Dropbox, and others. Using trusted, familiar services is part of the disguise: nothing about the web address screams "danger."
Then the page asks you to open the document, which means downloading a file, often inside a password-protected archive (the password is helpfully provided, which also lets the file slip past some email filters). When you run it, it does not install a tax form or an invoice. It installs a real remote monitoring and management tool, the category of software IT teams legitimately use to manage machines remotely.
From that point on, the attacker is connected to your computer through commercial software that is working exactly as designed. They can see your files, watch what you do, install more programs, and use your machine as a foothold. Nothing had to be "hacked." You installed the access yourself, believing you were opening a document.
Why your antivirus may wave it through
The clever part of this campaign is that the payload is not malware in the traditional sense. Remote monitoring and management software is legitimate, signed, commercial software. Millions of businesses run it on purpose. So a security tool that decides what to block based on "is this a known bad file" has a genuine problem here: the file is not bad. It is a real product being used for a bad reason.
The researchers make this point directly: detection cannot depend only on malware verdicts, reputation scores, or individual indicators, because the individual pieces keep changing and, in the case of the software itself, are not malicious at all. The infrastructure rotates daily. The RMM product can be swapped for a different vendor's tool at any time. What stays constant is the shape of the trick: a fake document, a page that hosts a download, and a file that quietly hands over remote control.
This is the same pattern we have written about before in other clothing. In the fake CNN "app" scam, a lookalike news site pushed a legitimate remote-administration tool as a "free app." In the fake COLDCARD "hardware audit" email, a phishing message told crypto owners to install an "audit tool" that was actually ConnectWise ScreenConnect, a real remote-access program the attacker controlled. Different bait, identical move: get a real remote-control tool onto your machine under a believable pretext.
Why this is hard to spot in the moment
The reason careful people fall for this is that every individual signal looks fine. The document is one you might genuinely receive. The page is on a service you have heard of. The download is a signed, real product. As we argued in why modern phishing no longer looks like phishing, the old tells, typos, ugly design, obviously fake addresses, have been engineered out. You are left trying to judge intent from a page that has been built specifically to look legitimate.
Asking yourself "does this look real?" is no longer a reliable test, because the answer is designed to be yes. The better question is "is this page actually who it claims to be, and should I be running this file at all?" That is a harder question to answer by eye, and it is exactly the question that has to be answered before you click download.
Where this can actually be stopped
If the file itself is a real product your antivirus has no reason to block, and the page is built to look legitimate, the defense has to move earlier, to the moment before the download, in the browser where you are standing.
That is where Haven works. Haven is a browser extension that checks whether a page truly is who it claims to be, rather than trusting how convincing it looks. When you land on a page impersonating a courier, a tax agency, or a document service to push a download, Haven flags it as a fake or impersonated page before you act on it. And because the whole attack turns on getting you to run a file, Haven pauses risky downloads so you can stop and check before something lands on your machine, instead of after. You can read more about how that works on our download protection page.
To be precise about what this does and does not do: Haven works at the delivery step, the fake page and the download, which is the point where an individual can actually intervene. It is a browser extension, not an endpoint security product. Once remote monitoring software is already installed and running on a computer, detecting and removing that activity is the job of endpoint protection and, for organizations, a security team, not a browser extension. Haven's role is to keep you from reaching that step: to catch the impersonated page and the unexpected download before the remote-access tool ever gets installed.
If you think you already installed something like this, treat the computer as compromised: disconnect it from the internet, change important passwords from a different device, and get help from a trusted professional or your IT team.
For small teams, where a single person opening a fake invoice can expose the whole business, Haven for Business extends this browser-level check across everyone's browser. That matters here specifically because the campaign leans on documents that land in work inboxes, invoices, tax notices, shipping updates, and small businesses often have no security team standing between an employee and a convincing fake.
The lesson underneath this campaign is the one running through every modern attack: you can no longer trust that something is safe just because it looks routine and comes wrapped in familiar logos. The document you were expecting is exactly what a good attacker will pretend to send. The safest habit is to confirm what a page really is, and think twice about what it wants you to run, before you hand over the keys.
About Haven
Haven is a browser extension that helps people make safer trust decisions online, before a scam can cost anything. It works at the moment someone is about to click a link or enter a password, flagging fake and impersonated login pages, suspicious links, and look-alike sites, and pausing risky downloads. Rather than only checking a page against a list of known-bad sites, Haven analyzes the actual page in front of the user, so it can catch brand-new and convincing fakes that other tools miss.
Haven is free for individual use. For teams, Haven for Business extends this browser-level protection across every employee. Haven is operated by MirrorTab, Inc.