logo

Who's the bossware? Ransomware slingers like employee monitoring tools, too

ID: 43147e67-1f33-5f20-81e9-d35448787889

STIX ID: report--43147e67-1f33-5f20-81e9-d35448787889

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Huntress observed two separate intrusions in which attackers installed Net Monitor for Employees and used SimpleHelp RMM to perform hands-on-keyboard reconnaissance, manipulate user accounts, attempt to disable Defender, and try to deploy Crazy/ VoidCrypt ransomware; attackers also monitored for cryptocurrency-related keywords indicating theft motivations. Shared artifacts (vhost.exe, IP 160.191.182.41) suggest a common actor; Huntress recommends enabling MFA, restricting and auditing remote access and RMM/employee-monitoring tools, and monitoring for unusual process execution chains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.