Sophos X-Ops reported that a phishing campaign tracked as STAC6405 used invitation-themed lures to trick targets into installing legitimate remote monitoring and management tools, including LogMeIn Resolve and ScreenConnect, giving attackers unattended remote access. The activity was first observed in April 2025, peaked in October and November 2025, and affected more than 80 organizations, primarily in the United States. Sophos said some phishing links were still active at the time of reporting, indicating the campaign may still be ongoing.
In most intrusions, the attackers stopped after establishing remote access, suggesting the operation may support initial access brokerage or maintain dormant persistence for later use. In two cases, however, the compromise advanced to second-stage activity: one intrusion deployed a HeartCrypt-packed infostealer that hid the mouse cursor, injected into csc.exe, contacted 45[.]56.162.138, and stole browser, wallet, and system data; another used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to obtain interactive access before defenders contained the incident.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
At the time of Sophos reporting, some phishing links tied to STAC6405 were still active, indicating the campaign may still have been ongoing. In most observed cases, the attackers stopped after establishing remote access, suggesting possible initial access brokerage or dormant persistence.
The phishing campaign was most active during October and November 2025. Sophos said the activity ultimately affected more than 80 organizations, primarily in the United States.
In a separate incident, the attackers used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to gain interactive access. The customer contained the intrusion before further activity was described.
In one incident following initial remote access, the attackers quickly moved to second-stage activity by deploying a HeartCrypt-packed infostealer. The malware hid the mouse cursor, injected into csc.exe, contacted 45.56.162.138, and stole browser, wallet, and system data.
Sophos X-Ops first saw evidence of the invitation-themed phishing campaign tracked as STAC6405 in April 2025. The lures were used to trick targets into installing legitimate remote monitoring and management tools for attacker-controlled unattended access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcekaseya.com
Open sourceblackpointcyber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.