AhnLab’s ASEC reported phishing campaigns distributing legitimate remote monitoring and management (RMM) tools, including ConnectWise ScreenConnect, FleetDeck, Datto RMM, SimpleHelp, JumpCloud, and N-able. Attackers used document-themed attachments, PDF links, phishing pages, and scripts to persuade users to install agents configured for attacker-controlled remote access. The report identifies deployment identifiers, configuration fields, and associated infrastructure that can support detection. Because these tools also serve legitimate administrative purposes, malicious installations can complicate security monitoring and blocking. ASEC did not attribute the newly identified campaigns to a specific threat actor.
Separate government advisories illustrate how remote-access capabilities fit into ransomware intrusions, without establishing a connection to these phishing campaigns. The FBI, CISA, and HHS documented ALPHV/BlackCat affiliates using social engineering, remote-access and tunneling tools, credential theft, and cloud-based data exfiltration; healthcare was the most frequently victimized sector among nearly 70 leaked victims after mid-December 2023. An updated Play ransomware advisory reported approximately 900 allegedly affected entities known to the FBI as of May 2025 and described access through valid accounts and vulnerable public-facing applications, including activity exploiting SimpleHelp vulnerability CVE-2024-57727. Defenders should scrutinize unexpected RMM installations and their deployment configurations, secure remote access with phishing-resistant MFA, rapidly patch exploited vulnerabilities, segment networks, and maintain offline or immutable backups.

Get the infrastructure and lures behind it.
17 events from the most recent confirmed update back to the earliest known activity.
In the second half of 2026, ScreenConnect was distributed through LNK, BAT, and VBS files with filenames suggesting phishing email attachments. Examples impersonated a Dropbox shared PDF, a Zoom installer, and a wire receipt.
ASEC reported attackers distributing Syncro, ConnectWise ScreenConnect, NinjaOne, and SuperOps through video files and phishing email attachments.
The FBI, CISA, and ACSC updated the Play ransomware advisory with newly observed tactics and refreshed indicators, removing outdated indicators and adding current ones. The update incorporated FBI investigative findings through January 2025.
By May 2025, the FBI was aware of approximately 900 affected entities allegedly exploited by Play ransomware actors.
CVE-2024-57727 in SimpleHelp remote monitoring and management software was disclosed. The Play advisory subsequently linked post-disclosure exploitation to multiple ransomware groups and initial access brokers with ties to Play operators.
The FBI, CISA, and HHS updated the ALPHV/BlackCat advisory with investigative findings observed through February 2024, including victim-specific notification emails and updated indicators. The update reported that healthcare had been the most commonly victimized sector among nearly 70 leaked victims since mid-December 2023.
The initial version of the joint #StopRansomware cybersecurity advisory on ALPHV/BlackCat was published, expanding on the FBI's earlier FLASH report.
The FBI, CISA, and Australia's ACSC published a joint #StopRansomware advisory covering Play ransomware and its associated indicators and tactics.
Operational action was taken against the ALPHV/BlackCat group and its infrastructure in early December 2023.
A further Play ransomware incident was observed in Australia in November 2023.
The first observed Play ransomware incident in Australia occurred in April 2023.
ALPHV/BlackCat administrators announced “ALPHV Blackcat Ransomware 2.0 Sphynx,” a rewritten version with improved defense evasion and additional tooling. The update supports encryption of Windows and Linux devices and VMware instances.
Play ransomware activity began affecting businesses and critical infrastructure across North America, South America, and Europe.
The FBI released its FLASH report, “BlackCat/ALPHV Ransomware Indicators of Compromise,” documenting indicators associated with the ransomware operation.
ASEC documented phishing cases installing FleetDeck, Datto RMM, SimpleHelp, JumpCloud, and N-able through PDF links, Adobe-themed pages, HTML scripts, and a DocuSign-themed lure. The report disclosed deployment identifiers, agent configuration details, and infrastructure indicators without attributing the newly identified cases to a specific threat actor.
After disclosure of CVE-2024-57727, multiple ransomware groups, including initial access brokers with ties to Play operators, exploited the vulnerability to achieve remote code execution using PowerShell.
Following the operational action against ALPHV, an administrator posted encouragement for affiliates to target hospitals. The subsequent federal advisory assessed that this likely influenced increased healthcare targeting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 76 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.