Phishing Attack Targets Over 80 Organizations with RMM Tools

A recent phishing campaign has compromised more than 80 organizations by exploiting Remote Monitoring and Management tools.

3 min readCybersecurity

A significant phishing operation has been detected that has been targeting various organizations since at least April 2025. This campaign utilizes legitimate Remote Monitoring and Management (RMM) software to gain ongoing remote access to affected systems. Named VENOMOUS#HELPER, this operation has reportedly impacted over 80 entities, predominantly located in the United States, as indicated by findings from Securonix. The campaign shows connections to other known threat clusters, suggesting a broader strategy at play. The attackers leverage trusted software such as SimpleHelp and ScreenConnect to facilitate their malicious activities, allowing them to bypass traditional security measures. Organizations are urged to enhance their security protocols and remain vigilant against such sophisticated phishing tactics that exploit legitimate tools for unauthorized access.

Cybersecurity