Bleeping Computer reports that the Crazy ransomware gang is exploiting legitimate employee monitoring software and the SimpleHelp remote support tool to gain and maintain persistence within corporate networks, evade detection, and prepare for ransomware deployment.Researchers at Huntress observed threat actors using Net Monitor for Employees Professional and SimpleHelp to achieve stealthy remote access. Attackers installed the monitoring agent using msiexec.exe, enabling them to view victim desktops, transfer files, and execute commands. For redundant persistence, they installed the SimpleHelp client via PowerShell, often disguising its filename to mimic legitimate system processes like vshost.exe or OneDrive files. The attackers also attempted to disable Windows Defender and configured SimpleHelp to alert them to activity involving cryptocurrency wallets or other remote access tools, indicating preparations for ransomware deployment and potential theft. Overlapping command and control infrastructure and reused filenames suggest a single actor is behind these intrusions.The increasing use of legitimate remote management and monitoring tools by threat actors highlights the need for organizations to closely monitor for unauthorized installations of such software. Given that these breaches were facilitated by compromised SSL VPN credentials, enforcing multi-factor authentication on all remote access services is crucial to prevent unauthorized network access and subsequent attacks.Source: Bleeping Computer
Ransomware, Threat Intelligence
Ransomware gang abuses legitimate software for network persistence
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
