logo

Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations

ID: 9aaccb14-2d16-5844-88d5-be6878fadff8

STIX ID: report--9aaccb14-2d16-5844-88d5-be6878fadff8

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-28

...
...

Huntress observed two related intrusions (late Jan–early Feb 2026) where attackers leveraged Net Monitor for Employees Professional and SimpleHelp RMMs—disguising services and renaming binaries—to establish persistent remote access, conduct hands-on-keyboard reconnaissance, and attempt deployment of Crazy ransomware; overlapping IOCs (shared IPs, reused vhost.exe) and consistent tradecraft suggest a single financially motivated operator focused on ransomware and cryptocurrency theft. The report provides IOCs, log evidence, and defensive recommendations including MFA, least privilege, segmentation, application control, and monitoring for Defender/EDR tampering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.