Sophos X-Ops reported that a phishing campaign tracked as STAC6405 used invitation-themed lures to trick targets into installing legitimate remote monitoring and management tools, including LogMeIn Resolve and ScreenConnect, giving attackers unattended remote access. The activity was first observed in April 2025, peaked in October and November 2025, and affected more than 80 organizations, primarily in the United States. Sophos said some phishing links were still active at the time of reporting, indicating the campaign may still be ongoing.
In most intrusions, the attackers stopped after establishing remote access, suggesting the operation may support initial access brokerage or maintain dormant persistence for later use. In two cases, however, the compromise advanced to second-stage activity: one intrusion deployed a HeartCrypt-packed infostealer that hid the mouse cursor, injected into csc.exe, contacted 45[.]56.162.138, and stole browser, wallet, and system data; another used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to obtain interactive access before defenders contained the incident.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
At the time of Sophos reporting, some phishing links tied to STAC6405 were still active, indicating the campaign may still have been ongoing. In most observed cases, the attackers stopped after establishing remote access, suggesting possible initial access brokerage or dormant persistence.
The phishing campaign was most active during October and November 2025. Sophos said the activity ultimately affected more than 80 organizations, primarily in the United States.
In a separate incident, the attackers used a ScreenConnect-based payload bundled with Java components and a likely SimpleHelp-related remote access binary to gain interactive access. The customer contained the intrusion before further activity was described.
In one incident following initial remote access, the attackers quickly moved to second-stage activity by deploying a HeartCrypt-packed infostealer. The malware hid the mouse cursor, injected into csc.exe, contacted 45.56.162.138, and stole browser, wallet, and system data.
Sophos X-Ops first saw evidence of the invitation-themed phishing campaign tracked as STAC6405 in April 2025. The lures were used to trick targets into installing legitimate remote monitoring and management tools for attacker-controlled unattended access.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcekaseya.com
Open sourceblackpointcyber.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.