216.73.216.6

Pivoting From PayTool: Tracking Various Frauds and E-Crime Targeting Canada

· Published 27/01/2026 13:03 · Modified 27/01/2026 17:44

Export JSON

Essential information

Published
27/01/2026 13:03
Modified
27/01/2026 17:44
Tags
2026-01-27 brand impersonation canada data harvesting financial fraud government impersonation phishing sms scams typosquatting underground forums
Related entities
1 intrusion sets (apt), 3 techniques (mitre), 9 others

Description

This investigation exposes a complex fraud ecosystem targeting Canadians through impersonation of government services and trusted brands. Attackers exploit digital dependencies for transportation, taxation, parcel delivery, and travel using convincing campaigns. The activity is linked to the 'PayTool' framework, specializing in traffic violation scams. Additional infrastructure impersonates Revenue Agency, Air , and Post. Threat actors commercialize these campaigns on , selling kits mimicking official services. Victims are lured via SMS and malicious ads, using high-pressure tactics. The infrastructure employs fake validation phases and fraudulent payment gateways to harvest personal and financial data. The campaign's scope spans multiple provinces, utilizing shared hosting and domain generation patterns for scalability.

External references