An active phishing campaign has targeted more than 80 organizations since at least April 2025, mainly in the U.S., and used legitimate remote monitoring and management software to keep persistent access on infected systems, according to a technical analysis.
KEY FACTS
- Campaign VENOMOUS#HELPER has been linked to phishing and remote access activity.
- Impact More than 80 organizations were affected, most of them in the U.S.
- Tools The attackers used SimpleHelp and ScreenConnect RMM software.
- Entry point Emails impersonated the U.S. Social Security Administration.
The report says the phishing emails told recipients to verify their address and download a supposed SSA statement. The link led to a legitimate but compromised Mexican business website, which then redirected victims to a second attacker-controlled domain hosting the malicious file.
The executable was packaged with JWrapper and installed SimpleHelp on Windows systems. It set itself up as a service with Safe Mode persistence, used a self-healing watchdog, checked for security products through WMI, and polled for user presence on a fixed schedule.
Once installed, the remote access client obtained elevated privileges, including SYSTEM-level access, which allowed the operator to view screens, inject keystrokes, and reach user resources. The disclosure says ScreenConnect was also installed as a fallback channel if the first tool was blocked.
The researchers said the use of two legitimate RMM products created redundant access paths that could survive detection or removal of one channel. The report said the activity may fit a financially motivated initial access broker or ransomware precursor pattern, but the operator was not identified.
WHY IT MATTERS
The campaign shows how signed administrative tools can be abused to bypass conventional defenses and keep long-term access on victim systems. That makes phishing attacks harder to detect and gives attackers a reliable foothold for follow-on intrusion activity.

