IT-Helpdesk Impersonation Replaces Ransomware Noise

SRG is lowering the bar for extortion. It no longer needs to lock up systems first; it can win by getting an employee to start a live support session and then quietly take data through that trusted channel. The group now poses as internal IT or security, uses screen-sharing, and pushes a legitimate remote-access tool into the session. The reporting says SRG has moved away from encryption entirely and is using this pure exfiltration model across victims instead of depending on malware or file encryption. That shifts the defender's problem from noisy ransomware recovery to trust abuse. If staff will join a screen-share or install remote-support software for an impostor, SRG can scale the same play across more targets with far less friction.

Part of the PlainSec briefing for 2026-06-09

Every edition of this story: IT-Helpdesk Impersonation Replaces Ransomware Noise

Sources