Phishing Campaign Exploits RMM Tools to Target Organizations

Phishing Campaign Exploits RMM Tools to Target Organizations

First seen 4 May 2026, 22:37 UTC Darkreadingwww.cybersecuritydive.comHuntresswww.securonix.comen.wikipedia.org 83% similarity 71.0

Article Content

Browse articles
ThreatCluster

A phishing campaign known as VENOMOUS#HELPER has affected over 80 organizations, primarily in the US, Western Europe, and Latin America. Attackers are utilizing legitimate remote monitoring and management (RMM) tools, specifically SimpleHelp and ScreenConnect, to maintain persistent access to compromised systems. The campaign has been active since at least April 2025, employing phishing emails that impersonate the US Social Security Administration to lure victims into downloading malicious executables. These tools allow attackers to blend their activities with normal operations, making detection difficult. The use of RMM tools for attacks has surged, with a reported 277% increase in misuse in 2025. Federal officials warn that similar techniques could target sensitive national security systems. The NSA has released guidance to help protect federal workers from these threats. The ongoing nature of the campaign indicates a significant risk to organizations across various sectors.

Key Points: • Over 80 organizations have been impacted by the VENOMOUS#HELPER phishing campaign. • Attackers are using legitimate RMM tools like SimpleHelp and ScreenConnect to evade detection. • The campaign has been active since at least April 2025, with a significant increase in RMM tool misuse.

ThreatCluster AI

Timeline

2025-04-01
VENOMOUS#HELPER campaign becomes active.
2025-09-01
Sample phishing email claiming Geek Squad subscription identified.
2025-12-01
Research shows 277% increase in RMM tool misuse.
2026-05-04
Current articles published detailing ongoing attacks.

Community

Browse all →