Who's the bossware? Ransomware slingers like employee monitoring tools, too
ID: 43147e67-1f33-5f20-81e9-d35448787889
STIX ID: report--43147e67-1f33-5f20-81e9-d35448787889
Feed Name: The Register (Security)
Huntress observed two separate intrusions in which attackers installed Net Monitor for Employees and used SimpleHelp RMM to perform hands-on-keyboard reconnaissance, manipulate user accounts, attempt to disable Defender, and try to deploy Crazy/ VoidCrypt ransomware; attackers also monitored for cryptocurrency-related keywords indicating theft motivations. Shared artifacts (vhost.exe, IP 160.191.182.41) suggest a common actor; Huntress recommends enabling MFA, restricting and auditing remote access and RMM/employee-monitoring tools, and monitoring for unusual process execution chains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
