Fake SSA Emails Drive Venomous#Helper Phishing Campaign
ID: fc2f6391-1e9c-5ad4-bf5b-40220bca09eb
STIX ID: report--fc2f6391-1e9c-5ad4-bf5b-40220bca09eb
Feed Name: Infosecurity Magazine (News)
Threat Score
A long-running phishing campaign called Venomous#Helper has compromised over 80 organizations (primarily in the US) by delivering signed RMM binaries (SimpleHelp and ScreenConnect) via SSA-themed lures and compromised websites; the attackers achieve silent, persistent dual-channel access, use evasion techniques (e.g., renamed WMIC binary, SafeBoot persistence, watchdogs), and likely operate as financially motivated initial access brokers or ransomware precursors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
