Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.
Arctic Wolf detailed how affiliates of the Anubis ransomware group break in and stay hidden, drawing on intrusions across healthcare, finance, and manufacturing this year. Initial access came from stolen VPN credentials and from exploiting CitrixBleed 2, a NetScaler flaw that leaks session tokens from memory and lets attackers bypass multi-factor authentication. Once inside, the affiliates leaned on legitimate remote-management software such as ScreenConnect, Zoho Assist, and MeshAgent to blend in with normal IT activity, moving through networks with RDP and PsExec toward domain controllers, backups, and storage devices. They stole data using common cloud-transfer tools before encrypting anything, which is exactly where defenders have the best chance to catch them.
Securonix tracked a phishing campaign called VENOMOUS#HELPER that has hit 80+ organizations (mostly in the US) since April 2025 by getting employees to install legitimate remote-monitoring software they think is a Social Security Administration document. The lure is a fake SSA email asking the recipient to download their statement; the link points to a compromised Mexican business website hosting a SimpleHelp installer. Once installed, the attackers gain SYSTEM-level access, then quietly install ConnectWise ScreenConnect as a backup channel. The pattern aligns with initial-access broker activity: quiet persistence, then sale or hand-off to ransomware operators.