Threats · 133 days ago
The real problem is not the phishing lure. It is that the campaign turns trusted remote management software into persistent access, so removing one implant may not clear the intrusion. The dual use of SimpleHelp and ScreenConnect gives attackers a fallback channel when defenders block one path.
Securonix says the VENOMOUS#HELPER campaign has hit more than 80 organizations, mostly in the U.S., and has been active since at least April 2025. The lure impersonates the U.S. Social Security Administration, and the payloads are customized SimpleHelp and ScreenConnect RMM tools used to bypass defenses.
That setup points to an access-broker or ransomware-prep operation, not a one-off phishing run. The persistence risk remains even after initial detection, because the second RMM can preserve access after the first is removed.
3 sources covering this story
Fake SSA Emails Drive Venomous#Helper Phishing Campaign
Venomous#Helper attackers impersonate the US Social Security Administration to deploy signed RMM software and maintain persistent access across US networks
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
VENOMOUS#HELPER phishing campaign active since April 2025 has impacted 80+ organizations, mainly in the U.S., using SSA-themed lures.
RMM Tools Fuel Stealthy Phishing Campaign
Attackers are abusing two remote monitoring and management (RMM) tools to evade detection in a campaign that has impacted over 80 organizations so far.
Part of the PlainSec briefing for 2026-05-06