HomeSecurityCrazy ransomware: Abuse of legitimate employee monitoring tool

Crazy ransomware: Abuse of legitimate employee monitoring tool

A particularly worrying attack pattern is being uncovered by recent cybersecurity research: a member of the Crazy ransomware appears to be abusing legitimate employee monitoring and remote support toolsin order to maintain access to corporate networks, evade detection, and pave the way for eventual ransomware deployment.

Crazy ransomware

This practice shows how modern threat actors no longer rely exclusively on malware, but instead leverage "normal" tools used daily by businesses.

Abuse of employee monitoring tools

The breaches were discovered by researchers at Huntress, who investigated incidents where attackers installed Net Monitor for Employees Professional in conjunction with the remote access tool SimpleHelp.

See also: Coinbase Cartel: Steals data from major companies

What makes the case particularly dangerous is that these tools can easily be "lost" within the daily administrative activity of an organization, as they resemble applications IT.

In one of the attacks, the attackers used Windows Installer via the msiexec.exe, installing the software directly from the developer's official website. This way, they avoided raising suspicions that suspicious executables usually cause.

Full interactive access to victims

Once the tool was installed, the attackers gained essentially complete control of the systems. Net Monitor for Employees allowed them to:

  • view the victim's desktop in real time
  • to transfer files
  • execute commands remotely

This access turns a simple monitoring tool into a powerful ransomware espionage and preparation mechanism .

Crazy ransomware: Abuse of legitimate employee monitoring tool

Enable administrator accounts

The perpetrators also attempted to escalate their privileges by activating the local administrator account via the command:

net user administrator /active:yes

Such moves are a classic stage of privilege escalation, providing attackers with greater control and the ability to install additional payloads.

See also: From Ransomware to Permanent Access: The Rise of Digital Parasites

SimpleHelp: Backup door to the network

For added durability, the hackers downloaded the SimpleHelp remote access software via PowerShell, using deceptive file names such as vshost.exe , which resembled legitimate Visual Studio components.

In several cases, SimpleHelp disguised itself even further, with routes such as:

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

C:\ProgramData\OneDriveSvc\OneDriveSvc.exe

So, even if the monitoring tool (Net Monitor) was removed, the attackers maintained permanent access to the environment.

Attempts to disable Windows Defender

Researchers also observed attempts to disable Windows Defenderby stopping and deleting related services. This tactic is a clear indication that the attackers were preparing the ground for the final phase of the attack.

Crypto monitoring and remote access tools

In one of the most interesting findings, the perpetrators set up monitoring rules in SimpleHelp to be notified when users accessed cryptocurrency wallets or remote management tools.

According to Huntress, keywords such as metamask, exodus, binance, etherscan, as well as RDP, AnyDesk, TeamViewer, and VNC were being monitored.

See also: Warlock Ransomware breached SmarterTools

This strategy shows that attacks are not limited to data encryption, but are often also linked to potential theft of digital assets.

Crazy ransomware: Abuse of legitimate employee monitoring tool

The growing trend of using legal tools

Although only one incident resulted in the deployment of Crazy ransomware, Huntress believes that the same operator is behind both incidents, as reuse of the same filename and C2 infrastructure was observed.

The use of legitimate remote administration tools has now become a key tactic of ransomware groups because it allows them to "blend in" with normal network traffic.

What should organizations do?

Huntress warns that businesses should closely monitor unauthorized installations of remote monitoring and support tools.

At the same time, because the breaches were initiated by compromised SSL VPN credentials, it is critical to implement multi-factor authentication (MFA) on all remote access services.

In an era where ransomware attacks are becoming increasingly "silent", prevention and constant surveillance are the strongest defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS