logo

Kickidler employee monitoring software abused in ransomware attacks

ID: aef4528f-9e62-576e-883e-cc497c0327f0

STIX ID: report--aef4528f-9e62-576e-883e-cc497c0327f0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-05-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ransomware affiliates (Qilin and Hunters International) used malvertised, trojanized RVTools to install the SMOKEDHAM backdoor and legitimate Kickidler employee-monitoring software to capture credentials and screen activity, then deployed ransomware that encrypted VMware ESXi VMDK files; the report warns of attackers abusing legitimate RMM/monitoring tools and recommends auditing and restricting remote access software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.