logo

Fake SSA Emails Drive Venomous#Helper Phishing Campaign

ID: fc2f6391-1e9c-5ad4-bf5b-40220bca09eb

STIX ID: report--fc2f6391-1e9c-5ad4-bf5b-40220bca09eb

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-05-05

Date Updated: 2026-05-05

...
...

A long-running phishing campaign called Venomous#Helper has compromised over 80 organizations (primarily in the US) by delivering signed RMM binaries (SimpleHelp and ScreenConnect) via SSA-themed lures and compromised websites; the attackers achieve silent, persistent dual-channel access, use evasion techniques (e.g., renamed WMIC binary, SafeBoot persistence, watchdogs), and likely operate as financially motivated initial access brokers or ransomware precursors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.