logo

Cybercriminals Exploit Employee Monitoring and SimpleHelp Tools in Ransomware Attacks

ID: 01b32077-447c-5334-a887-7d301a28b404

STIX ID: report--01b32077-447c-5334-a887-7d301a28b404

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report describes two related intrusions in which threat actors abused legitimate remote monitoring and management tools (Net Monitor for Employees Professional and SimpleHelp) to establish persistence, conduct reconnaissance, and ultimately attempt to deploy Crazy ransomware (VoidCrypt family). Shared filenames (vhost.exe, encrypt.exe), overlapping C2 infrastructure (dronemaker.org, multiple IPs), and consistent techniques indicate a single operator or group; the actors also monitored cryptocurrency-related activity. Recommended defenses include enforcing MFA on remote access, hardening and monitoring VPN/RDP gateways, restricting administrative use of RMM tools, and applying network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.