Find notable cyber news and cases, enriched with sources, timelines, and signals.

APT phishing campaign abusing ScreenConnect, AnyDesk, and Atera

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A wave of phishing-led RMM abuse is giving APT groups initial access to systems and enabling persistence plus lateral movement inside compromised networks. The activity spans AnyDesk, ConnectWise ScreenConnect, and Atera, showing a broader operator pattern rather than a single-tool abuse case. Attackers are leveraging legitimate remote-management functions to turn trusted software into an intrusion path.

Related Happenings

GPU cryptomining malware using ScreenConnect and SEO poisoning

Malware Activity
H score16 First: 28.05.2026 00:31 Last: 28.05.2026 00:31 Sources 1

About this happening: A cryptojacking malware operation is spreading through SEO-poisoned download pages and, in some cases, AI chatbot recommendations, putting high-performance Windows s...

AI chatbot cryptojacking campaign targeting high-performance GPU users

Campaign
H score51 First: 27.05.2026 10:45 Last: 27.05.2026 10:45 Sources 1

About this happening: Microsoft warned of an active cryptojacking campaign that uses SEO poisoning and, in some cases, AI chatbot recommendations to steer users to malicious ZIP downloa...

MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy

Campaign
H score37 First: 06.05.2026 16:02 Last: 06.05.2026 16:02 Sources 1

About this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...

CloudZ RAT Pheno Microsoft Phone Link credential-theft activity

Malware Activity
H score24 First: 05.05.2026 13:03 Last: 05.05.2026 13:03 Sources 1

About this happening: The CloudZ RAT is now using the Pheno plugin to hijack Microsoft Phone Link sessions and steal SMS-based OTPs and other sensitive codes, increasing the risk of acc...

VENOMOUS#HELPER phishing campaign using RMM tools

Campaign
H score42 First: 04.05.2026 21:06 Last: 04.05.2026 21:06 Sources 1

About this happening: An active VENOMOUS#HELPER phishing campaign is using legitimate RMM software to establish persistent remote access to compromised hosts, putting over 80 organization...

Latest development: 05.05.2026 17:00

Securonix found the Venomous#Helper phishing campaign using emails impersonating the US Social Security Administration to send victims to gruta[.]com.mx, which served an SSA-branded harvesting page before redirecting to payload delivery from a separate compromised cPanel account. The campaign pairs a self-hosted SimpleHelp 5.0.1 instance with a ConnectWise ScreenConnect relay, and the downloaded JWrapper-packaged binary was signed by SimpleHelp Ltd with a valid Thawte certificate. In a one-hour observation, Securonix recorded 986 background process-creation events and WMIC execution through a renamed wmic.exe.bak copy to evade EDR rules.

Timeline

  1. 13.10.2025 18:45 2 articles · 9mo ago

    DarkAtlas reports phishing-led abuse of RMM tools

    Initial Disclosure

    DarkAtlas researchers report that advanced persistent threat groups are abusing AnyDesk, ConnectWise ScreenConnect, and Atera in phishing-led intrusions to gain unauthorized control of systems. The analysis says ScreenConnect is being repurposed through legitimate features such as unattended access, VPN functionality, REST API integration, and file transfer to establish persistence, move laterally within compromised networks, and conceal activity with an in-memory installer, custom URLs or invite links, persistent ScreenConnect.WindowsClient.exe service installation, and event log artifacts such as Security Event ID 4573 and Application Log events 100 and 101.

    Show sources