logo

RMM Tools Fuel Stealthy Phishing Campaign

ID: 839a51c2-e6d7-5669-b28e-9814c75df9e7

STIX ID: report--839a51c2-e6d7-5669-b28e-9814c75df9e7

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Jai Vijayan

...
...

VENOMOUS#HELPER is an active, targeted phishing campaign that lures victims with fake Social Security Administration statements to deploy malicious executables which install two legitimately signed RMM tools (SimpleHelp and ScreenConnect). Attackers use SimpleHelp for scripted/background monitoring and ScreenConnect for interactive control, enabling stealthy persistence and hands-on access; the operation has impacted more than 80 organizations across multiple regions and is assessed as likely financially motivated (IAB or ransomware precursor).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.