Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
ID: 26143129-679b-5e29-a702-c391ab64a8dd
STIX ID: report--26143129-679b-5e29-a702-c391ab64a8dd
Feed Name: The Hacker News
**Active phishing campaign (VENOMOUS#HELPER)**: Since at least April 2025, attackers have distributed JWrapper-packaged Windows executables via SSA-themed phishing that install a customized SimpleHelp RMM as a persistent Windows service (Safe Mode persistence, self-healing), elevate to SYSTEM using AdjustTokenPrivileges/elev_win.exe, and deploy ConnectWise ScreenConnect as a fallback, enabling long-term interactive access across more than 80 organizations while evading signature-based defenses by using legitimately signed RMM software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
