Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Jason Momoa’s daughter wears wired headphones as an accessory

Oliver Tree’s mother shares heartbreaking post

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Phishing campaign using SimpleHelp and ScreenConnect RMM tools hits over 80 organizations
Celebrities

Phishing campaign using SimpleHelp and ScreenConnect RMM tools hits over 80 organizations

By May 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMay 4, 2026Network security/endpoint security

Since at least April 2025, we have observed active phishing campaigns targeting multiple vectors, using legitimate remote monitoring and management (RMM) software as a way to establish persistent remote access to compromised hosts.

According to Securonix, the operation, codenamed VENOMOUS#HELPER, has affected more than 80 organizations, most of them in the United States. This overlaps with a cluster previously tracked by Red Canary and Sophos, which named it STAC6405. It is not clear who is behind this campaign, but the cybersecurity firm said it is working with a financial Initial Access Broker (IAB) or a ransomware precursor operation.

“In this case, the customized SimpleHelp and ScreenConnect RMMs were legally installed by the unsuspecting victim and are therefore being used to evade defenses,” researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee said in a report shared with Hacker News.

Aside from the fact that detection can be avoided using legitimate RMM tools, we can see that both SimpleHelp and ScreenConnect deployments attempt to create a “redundant dual channel access architecture” that allows them to continue operating even if one is detected and blocked.

It all starts with a phishing email impersonating the U.S. Social Security Administration (SSA), which instructs recipients to verify their email address and click on a link embedded in the message to download a statement purporting to be from SSA. This link points to a legitimate but compromised Mexican business website (“gruta.com”).[.]mx”), a deliberate strategy to evade email spam filters.

An “SSA statement” is then downloaded from a second attacker-controlled domain (“server.cubatiendaalimentos.com”).[.]mx”) is the executable file responsible for distributing the SimpleHelp RMM tool. The attackers are believed to have accessed a single cPanel user account on a legitimate hosting server to stage the binaries.

As soon as a victim opens a JWrapper-packaged Windows executable thinking it is a document, the malware installs itself as a Windows service with safe mode persistence, verifies that it is running with a “self-healing watchdog” that automatically restarts if it is killed, periodically enumerates registered security products using the root\SecurityCenter2 WMI namespace every 67 seconds, and polls for the presence of a user every 23 seconds.

To facilitate fully interactive desktop access, the SimpleHelp remote access client obtains SeDebugPrivilege via AdjustTokenPrivileges and uses the legitimate executable associated with the software, “elev_win.exe”, to obtain SYSTEM level privileges. This allows operators to read the screen, enter keystrokes, and access user context resources.

This elevated remote access is exploited to download and install ConnectWise ScreenConnect to provide a fallback communication mechanism if the SimpleHelp channel goes down.

“The introduced version of SimpleHelp (5.0.1) provides a comprehensive set of remote management capabilities,” the researchers said. “Victim organizations are left with the ability for attackers to return at any time and silently execute commands on users’ desktop sessions, transfer files bi-directionally, and pivot to adjacent systems, while standard antivirus and signature-based controls only recognize duly signed software from trusted UK vendors.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleElon Musk’s only AI expert witness in OpenAI trial raises concerns about AGI arms race
Next Article Imagery AI models outpace chatbot upgrades to drive app growth

Related Posts

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Rama Dowaj Styles Upcycled Knicks Shirt by Claire Sullivan

June 18, 2026

New York Knicks’ most stylish players

June 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Jason Momoa’s daughter wears wired headphones as an accessory

Oliver Tree’s mother shares heartbreaking post

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

President Trump to headline America’s 250th anniversary celebration after artist declines

Trending Posts

Jason Momoa’s daughter wears wired headphones as an accessory

June 19, 2026

Oliver Tree’s mother shares heartbreaking post

June 19, 2026

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

June 19, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.