Kickidler employee monitoring software abused in ransomware attacks
ID: aef4528f-9e62-576e-883e-cc497c0327f0
STIX ID: report--aef4528f-9e62-576e-883e-cc497c0327f0
Feed Name: Bleeping Computer
Threat Score
Ransomware affiliates (Qilin and Hunters International) used malvertised, trojanized RVTools to install the SMOKEDHAM backdoor and legitimate Kickidler employee-monitoring software to capture credentials and screen activity, then deployed ransomware that encrypted VMware ESXi VMDK files; the report warns of attackers abusing legitimate RMM/monitoring tools and recommends auditing and restricting remote access software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
