logo

Crazy ransomware gang abuses employee monitoring tool in attacks

ID: 5f136712-d404-54ca-8b95-9cce8b87c4de

STIX ID: report--5f136712-d404-54ca-8b95-9cce8b87c4de

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Huntress investigators observed a threat actor linked to the Crazy ransomware family abusing legitimate employee-monitoring software and SimpleHelp remote access to persist in corporate networks, exfiltrate/monitor activity (including cryptocurrency-related targets), disable Windows Defender, and prepare ransomware deployment after initial access via compromised SSL VPN credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.