BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Phishing Campaign Uses Legitimate RMM Tools for Access

VENOMOUS#HELPER phishing targets US orgs with RMM tools via Social Security impersonation

  • A phishing campaign codenamed VENOMOUS#HELPER has targeted over 80 organizations, primarily in the U.S., since at least April 2025.
  • Attackers use legitimate Remote Monitoring and Management (RMM) tools like SimpleHelp and ScreenConnect to establish persistent, stealthy access to compromised systems.
  • The campaign begins with emails impersonating the U.S. Social Security Administration, directing victims to download malware from compromised legitimate websites.
  • This operation aligns with a financially motivated Initial Access Broker (IAB) or a ransomware precursor, according to Securonix researchers.

Since at least April 2025, a sophisticated phishing campaign has been targeting organizations, primarily in the U.S., by weaponizing legitimate remote access software to hijack computer systems. Dubbed VENOMOUS#HELPER, this operation has impacted over 80 entities, as detailed in a report shared by Securonix researchers.

- Advertisement -

However, the attack cleverly begins with emails impersonating the U.S. Social Security Administration. Consequently, victims are tricked into clicking a link that leads to a compromised but legitimate Mexican business website.

This link ultimately delivers a malicious executable from a second attacker-controlled domain. The malware, packaged to look like a document, then installs the SimpleHelp RMM tool as a persistent Windows service.

Meanwhile, the deployed software establishes a robust foothold with a “self-healing watchdog” and frequent system checks. It also uses a legitimate component called “elev_win.exe” to gain powerful SYSTEM-level privileges on the infected machine.

This elevated access allows the attacker to read screens, inject keystrokes, and freely navigate the network. Furthermore, the operators often deploy a second RMM tool, ConnectWise ScreenConnect, as a redundant backup channel.

- Advertisement -

Researchers noted the campaign shares overlaps with clusters previously tracked by Red Canary and Sophos. The use of dual, signed RMM tools creates a significant challenge for standard antivirus defenses, which see only legitimate software.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitMine to Join Russell 1000, Spurring ETF Buying Wave

BitMine Immersion Technologies is set to join the large-cap Russell 1000 Index on June...

Crypto PACs Pour Millions into Texas Runoff Races

Two Texas congressional runoff elections this week are being heavily influenced by spending from...

Grayscale Names ETH, SOL, BNB, CC to Benefit from Act

Grayscale has identified four cryptocurrencies—Ethereum, Solana, BNB, and Canton—as the top beneficiaries of the...

Vitalik Buterin: Ethereum Foundation to “Shrink” as Top Exodus

Ethereum Foundation co-founder Vitalik Buterin announced the organization is shrinking to focus on core...

Bitcoin Risks $72K as Sell Pressure Mounts

Bitcoin faces a potential 7% drop toward $72,000 as bearish momentum strengthens on higher...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading