Cybercriminals Exploit Employee Monitoring and SimpleHelp Tools in Ransomware Attacks
ID: 01b32077-447c-5334-a887-7d301a28b404
STIX ID: report--01b32077-447c-5334-a887-7d301a28b404
Feed Name: GBHackers
The report describes two related intrusions in which threat actors abused legitimate remote monitoring and management tools (Net Monitor for Employees Professional and SimpleHelp) to establish persistence, conduct reconnaissance, and ultimately attempt to deploy Crazy ransomware (VoidCrypt family). Shared filenames (vhost.exe, encrypt.exe), overlapping C2 infrastructure (dronemaker.org, multiple IPs), and consistent techniques indicate a single operator or group; the actors also monitored cryptocurrency-related activity. Recommended defenses include enforcing MFA on remote access, hardening and monitoring VPN/RDP gateways, restricting administrative use of RMM tools, and applying network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
