Ransomware, Threat Intelligence

Ransomware gang abuses legitimate software for network persistence

Bleeping Computer reports that the Crazy ransomware gang is exploiting legitimate employee monitoring software and the SimpleHelp remote support tool to gain and maintain persistence within corporate networks, evade detection, and prepare for ransomware deployment.

Researchers at Huntress observed threat actors using Net Monitor for Employees Professional and SimpleHelp to achieve stealthy remote access. Attackers installed the monitoring agent using msiexec.exe, enabling them to view victim desktops, transfer files, and execute commands. For redundant persistence, they installed the SimpleHelp client via PowerShell, often disguising its filename to mimic legitimate system processes like vshost.exe or OneDrive files. The attackers also attempted to disable Windows Defender and configured SimpleHelp to alert them to activity involving cryptocurrency wallets or other remote access tools, indicating preparations for ransomware deployment and potential theft. Overlapping command and control infrastructure and reused filenames suggest a single actor is behind these intrusions.

The increasing use of legitimate remote management and monitoring tools by threat actors highlights the need for organizations to closely monitor for unauthorized installations of such software. Given that these breaches were facilitated by compromised SSL VPN credentials, enforcing multi-factor authentication on all remote access services is crucial to prevent unauthorized network access and subsequent attacks.

Source: Bleeping Computer

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds