logo

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

ID: 26143129-679b-5e29-a702-c391ab64a8dd

STIX ID: report--26143129-679b-5e29-a702-c391ab64a8dd

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-04

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

**Active phishing campaign (VENOMOUS#HELPER)**: Since at least April 2025, attackers have distributed JWrapper-packaged Windows executables via SSA-themed phishing that install a customized SimpleHelp RMM as a persistent Windows service (Safe Mode persistence, self-healing), elevate to SYSTEM using AdjustTokenPrivileges/elev_win.exe, and deploy ConnectWise ScreenConnect as a fallback, enabling long-term interactive access across more than 80 organizations while evading signature-based defenses by using legitimately signed RMM software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.