logo

Threat Actors Leveraging Employee Monitoring and SimpleHelp Tools to Deploy Ransomware Attacks

ID: 2b09d85a-6b70-599d-99bc-7e194fb7d771

STIX ID: report--2b09d85a-6b70-599d-99bc-7e194fb7d771

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cybercriminals are abusing legitimate employee-monitoring and remote-support tools (Net Monitor for Employees Professional and SimpleHelp) to establish long-term, stealthy access in corporate networks, rename agents to mimic Microsoft services (e.g., OneDriveSvc, OneDriver.exe), monitor screens for cryptocurrency-related activity (keywords like “wallet” and “Binance”), and prepare to deploy 'Crazy' ransomware while stealing funds; recommended mitigations include restricting software installation, enforcing MFA for remote accounts, auditing remote management tools, monitoring AV disablement attempts, and detecting suspicious program names.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.