Phishing Turns RMM Tools Into Redundant Backdoors

The real problem is not the phishing lure. It is that the campaign turns trusted remote management software into persistent access, so removing one implant may not clear the intrusion. The dual use of SimpleHelp and ScreenConnect gives attackers a fallback channel when defenders block one path. Securonix says the VENOMOUS#HELPER campaign has hit more than 80 organizations, mostly in the U.S., and has been active since at least April 2025. The lure impersonates the U.S. Social Security Administration, and the payloads are customized SimpleHelp and ScreenConnect RMM tools used to bypass defenses. That setup points to an access-broker or ransomware-prep operation, not a one-off phishing run. The persistence risk remains even after initial detection, because the second RMM can preserve access after the first is removed.

Part of the PlainSec briefing for 2026-05-06

Sources