A phishing campaign tracked as VENOMOUS#HELPER has compromised more than 80 organizations since at least April 2025, primarily in the United States, with additional victims in Western Europe and Latin America. Attackers used emails impersonating the U.S. Social Security Administration to drive targets to fake SSA pages hosted via compromised legitimate websites, including a Mexican domain used to help evade filtering. Victims who downloaded the fake SSA statement executable installed vendor-signed remote monitoring and management tools instead of conventional malware, giving the operators covert access through SimpleHelp and ConnectWise ScreenConnect.
Researchers said the malware chain deployed a self-hosted SimpleHelp 5.0.1 instance packaged with JWrapper and a separate ScreenConnect relay, creating redundant remote access if one channel was blocked. The installed tooling persisted as a Windows service, survived Safe Mode, polled for Wi-Fi status, firewall state, security products, user activity, and mouse movement, and in some cases renamed wmic.exe to evade name-based detections. Separate infrastructure analysis linked a signed SimpleHelp client to a five-server command-and-control cluster on 147.45.218.0/24, a Russian-language portal at dangerstock[.]online, and an exposed Cockpit dashboard, with Fortinet tracking the infrastructure as PALLASNET.M; Securonix assessed the broader activity as consistent with a financially motivated initial access broker or ransomware precursor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
On May 4, 2026, Dark Reading and The Hacker News reported Securonix's findings that VENOMOUS#HELPER had targeted more than 80 organizations using SimpleHelp and ScreenConnect. These reports did not introduce a separate incident but broadened public reporting on the campaign and its likely financially motivated initial-access or ransomware-linked nature.
On April 26, 2026, Securonix published research detailing the VENOMOUS#HELPER phishing campaign's use of dual legitimate RMM tools, SimpleHelp and ScreenConnect, for stealthy persistence and redundant remote access. The report described compromised websites, a fake SSA statement executable, host surveillance behavior, and evasion techniques such as renaming wmic.exe.
At the time of Breakglass publication, four of the five identified servers were still serving SimpleHelp customer download portals, while the primary 147.45.218.66 server had been hardened to agent-only behavior. Researchers also observed ScreenConnect used alongside SimpleHelp, indicating a dual-RAT persistence strategy.
On April 20, 2026, Breakglass published analysis connecting a signed SimpleHelp client sample to a five-server command-and-control cluster on 147.45.218.0/24 and a Russian-language portal at dangerstock[.]online. The report also noted a stolen Google Analytics certificate, an exposed Cockpit dashboard, and Fortinet tracking the infrastructure as PALLASNET.M.
Breakglass said new malware samples linked to the PALLASNET infrastructure were still appearing in April 2026, indicating the operation remained active. The analyzed sample was a legitimately signed SimpleHelp Remote Access Client configured to call back to 147.45.218.66:443.
Breakglass observed SimpleHelp deployments on the PALLASNET-associated infrastructure beginning in September 2025. The cluster ultimately included five servers, with several exposing SimpleHelp customer download portals.
Breakglass reported that the 147.45.218.0/24 subnet tied to the PALLASNET cluster was allocated in August 2025. Researchers later linked this network to a five-server command-and-control cluster supporting SimpleHelp and ScreenConnect-based remote access operations.
Securonix said the VENOMOUS#HELPER campaign has been active since at least April 2025, using phishing emails and fake U.S. Social Security Administration-themed pages to trick victims into downloading a malicious executable. The activity has affected more than 80 organizations, primarily in the United States, with additional victims in Western Europe and Latin America.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcedarkreading.com
Open sourcesecuronix.com
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.