Employee Monitoring and SimpleHelp Software Abused in Ransomware Operations
ID: 9aaccb14-2d16-5844-88d5-be6878fadff8
STIX ID: report--9aaccb14-2d16-5844-88d5-be6878fadff8
Feed Name: Huntress Blog
Huntress observed two related intrusions (late Jan–early Feb 2026) where attackers leveraged Net Monitor for Employees Professional and SimpleHelp RMMs—disguising services and renaming binaries—to establish persistent remote access, conduct hands-on-keyboard reconnaissance, and attempt deployment of Crazy ransomware; overlapping IOCs (shared IPs, reused vhost.exe) and consistent tradecraft suggest a single financially motivated operator focused on ransomware and cryptocurrency theft. The report provides IOCs, log evidence, and defensive recommendations including MFA, least privilege, segmentation, application control, and monitoring for Defender/EDR tampering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
