A phishing campaign has been active since April 2025, using legitimate Remote Monitoring and Management (RMM) software, specifically SimpleHelp and ScreenConnect , to establish continuous remote access to compromised computers.

The activity, codenamed VENOMOUS#HELPER , has affected over 80 organizations, mostly in the US, according to Securonix . It shares elements with groups monitored by Red Canary and Sophos. While the identity of the campaign’s perpetrators remains unclear, experts suggest it is a financially motivated Initial Access Broker (IAB) or a ransomware operation .
Researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee reported that custom RMMs SimpleHelp and ScreenConnect are being used to bypass defensesas they are legitimately installed by unsuspecting victims. The deployment of both tools suggests an attempt to create a “dual-channel access architecture,” allowing operations to continue even if one of them is detected and blocked.
See also: Abuse of Amazon SES for phishing attacks
How does the phishing attack work with SimpleHelp and ScreenConnect?
The campaign begins with a phishing email impersonating the U.S. Social Security Administration(SSA), asking the recipient to verify their email address and download a purported SSA statement by clicking a link embedded in the message. This link leads to a legitimate but compromised Mexican business website, suggesting a strategy to evade spam filters.
The “SSA statement” is downloaded from a second domain controlled by the attacker, and is an executable file responsible for delivering the RMM tool SimpleHelp. It is believed that the attacker gained access to a single cPanel user account on the legitimate hosting server to place the executable file.
When the victim opens the Windows executable that is “wrapped” with JWrapper, the malware installs itself as a Windows service with Safe Mode persistence. It ensures that it runs via a “self-healing watchdog” that automatically restarts it when it shuts down and periodically enumerates registered security products using the root\SecurityCenter2 WMI namespace every 67 seconds, checking for user presence every 23 seconds.

To facilitate fully interactive desktop access, the SimpleHelp remote access client obtains the SeDebugPrivilege via AdjustTokenPrivileges, while “elev_win.exe”, a legitimate executable associated with the software, is used to obtain SYSTEM level privileges. This allows the operator to read the screen, enter keystrokes, and access user resources.
See also: Finland: Arrest of teenager alleged to be a hacker of the Scattered Spider group
This elevated remote access is then used to download and install ConnectWise ScreenConnect, providing a fallback communication mechanism if the SimpleHelp channel goes down.
The expanded version of SimpleHelp (5.0.1) offers extensive remote administration capabilities. The victim organization remains vulnerable, allowing the attacker to return at any time, execute commands silently in the user's desktop session , transfer files back and forth, and jump to neighboring systems. Standard antivirus and signature-based scans only detect legitimately signed software from a trusted vendor in the UK.
Modern threats
The VENOMOUS#HELPER campaign clearly highlights the shift in cyberattacks towards more sophisticated and stealthy techniques, where attackers exploit legitimate remote administration tools to bypass traditional security systems. The use of SimpleHelp and ScreenConnect demonstrates that the modern threat is not based solely on obvious malware, but often hides behind trusted applications, making it particularly difficult to detect. At the same time, the strategy of creating a dual access channel demonstrates a high level of planning and operational adaptability on the part of the attackers.
See also: Silver Fox targets Russia and India with ABCDoor malware

Countering such attacks requires a multi-layered approach to cybersecurity, with an emphasis on educating users about phishing techniques, strengthening mechanisms for detecting suspicious activity , and continuously monitoring the installation of remote tools within corporate networks. This incident reminds us that human attention remains a critical defense factor and that organizations must continually invest in both technological solutions and the cultivation of a digital security culture to limit the likelihood of similar threats succeeding in the future.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
