A phishing lure built around fiscal paperwork shows how a legitimate remote management agent can become the real prize in an intrusion, even when no custom malware is involved.